Intel

AIKIDO-2026-10719

vm2 is vulnerable to Remote Code Execution

Remote Code ExecutionGHSA-47x8-96vw-5wg6 Published May 4, 2026

100

Critical Risk

This Affects:

JSvm2
0.0.1 - 3.10.5
Fixed in 3.11.0
Are you affected? Scan for Free

TL;DR

Cross-realm bridging lets guest code extract host-only symbols from objects that should stay opaque. Those symbols become part of a gadget chain that reaches host execution. The failure is a trust-boundary bug between guest and host realms. The update restricts how symbols and realm edges interact across the bridge.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.10.5.

How to fix this

Upgrade the vm2 library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform