Intel

AIKIDO-2026-10840

vm2 is vulnerable to Protection Mechanism Failure

Protection Mechanism FailureCVE-2026-47135 Published May 19, 2026

87

High Risk

This Affects:

JSvm2
3.0.0 - 3.11.3
Fixed in 3.11.4
Are you affected? Scan for Free

TL;DR

Sandbox code can reach the host Symbol.for registry and bypass write-trap checks on symbol-keyed properties. That leaks host symbols into the sandbox and enables prototype and capability attacks leading to host code execution. Affected builds run untrusted code in VM or NodeVM without the symbol hardening. The fix tightens symbol handling and write-trap coverage in the bridge layer.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vm2 is vulnerable to Protection Mechanism Failure in versions 3.0.0 - 3.11.3.

How to fix this

Upgrade the vm2 library to the patch version.