Intel

AIKIDO-2026-10808

vm2 is vulnerable to Remote Code Execution

Remote Code ExecutionCVE-2026-45411 Published May 14, 2026

98

Critical Risk

This Affects:

JSvm2
0.0.1 - 3.11.2
Fixed in 3.11.3
Are you affected? Scan for Free

TL;DR

Affected versions of vm2 contain a sandbox escape vulnerability that allows attackers to bypass the isolation mechanism and execute arbitrary commands on the host system. By abusing exception handling behavior in async generators and yield*, a malicious user can break out of the sandbox and achieve remote code execution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.11.2.

How to fix this

Upgrade the vm2 library to the patch version.