securityonline.info 8/20/2026, 2:10:55 PM · external

Critical CVE-2026-47686 vm2 flaw lets attackers escape sandbox

Critical CVE-2026-47686 vm2 flaw lets attackers escape sandbox
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical security advisory highlights three vulnerabilities in vm2, a JavaScript runtime that runs untrusted code within a sandbox. The most severe, CVE-2026-47686 (CVSS 9.9), allows for full sandbox escape, enabling remote code execution (RCE) via an Error.cause property exploit. Another vulnerability, CVE-2026-47698 (CVSS 9.8), bypasses existing mitigations and can manipulate host code. All affected versions are up to 3.11.5, and users are urged to update to version 3.11.6 immediately as patches are available. The presence of public proof-of-concept code increases the urgency to address these vulnerabilities.

View Primary Source Via securityonline.info

Article by CyberSIXT