Intel

AIKIDO-2026-10718

vm2 is vulnerable to Remote Code Execution

Remote Code ExecutionGHSA-qcp4-v2jj-fjx8 Published May 4, 2026

100

Critical Risk

This Affects:

JSvm2
0.0.1 - 3.10.5
Fixed in 3.11.0
Are you affected? Scan for Free

TL;DR

Internal trap plumbing can surface proxy handler objects to guest code under crafted conditions. With a forged target, guest code can invoke trap methods in a way that pivots to host execution. This is a direct sandbox escape primitive. The fix changes trap handling so leaked handlers cannot be turned into host execution gadgets.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.10.5.

How to fix this

Upgrade the vm2 library to the patch version.