Intel

AIKIDO-2026-10719

vm2 is vulnerable to Remote Code Execution

Remote Code ExecutionGHSA-47x8-96vw-5wg6 Published May 4, 2026

100

Critical Risk

This Affects:

JSvm2
0.0.1 - 3.10.5
Fixed in 3.11.0
Are you affected? Scan for Free

TL;DR

Cross-realm bridging lets guest code extract host-only symbols from objects that should stay opaque. Those symbols become part of a gadget chain that reaches host execution. The failure is a trust-boundary bug between guest and host realms. The update restricts how symbols and realm edges interact across the bridge.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.10.5.

How to fix this

Upgrade the vm2 library to the patch version.