Intel

AIKIDO-2026-10717

vm2 is vulnerable to Remote Code Execution

Remote Code ExecutionCVE-2026-24781 Published May 4, 2026

98

Critical Risk

This Affects:

JSvm2
0.0.1 - 3.10.5
Fixed in 3.11.0
Are you affected? Scan for Free

TL;DR

Guest code can influence inspection paths that rebuild host-side behavior from leaked representations. Attackers chain that to regain dangerous constructors and execute code on the host. The issue is a sandbox breakout through util.inspect-style plumbing rather than a normal guest API. The release hardens inspection-related bridging so those reconstructor gadgets are eliminated.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.10.5.

How to fix this

Upgrade the vm2 library to the patch version.