Vm2
This hub aggregates every CVE we track for Vm2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
82
CVEs tracked
51
Critical
14
High
0
In CISA KEV
Severity distribution
CRITICAL51HIGH14MEDIUM10
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
21
9
0
5
34
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Vm2.
- CVE-2026-93606vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species10.0
- CVE-2026-93605vm2 NodeVM before 3.12.1 Remote Code Execution via child_process10.0
- CVE-2026-93604vm2 3.11.8 Sandbox Escape via crypto.setFips7.2
- CVE-2026-93603vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function10.0
- CVE-2026-92963vm2 before 3.11.2 Information Disclosure via Internal State5.3
- CVE-2026-92962vm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.js
- CVE-2026-92961vm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit Bypass7.5
- CVE-2026-92959vm2 before 3.11.8 allowAsync Bypass via Promise Thenable7.1
- CVE-2026-92960vm2 before 3.11.6 Process-wide State Exposure via os and dns10.0
- CVE-2026-92958vm2 before 3.11.7 Denylist Bypass via fs/promises8.5
- CVE-2026-92957vm2 before 3.11.7 Authentication Bypass via node: Prefix9.9
- CVE-2026-92956vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming10.0
- CVE-2026-92955vm2 before 3.11.8 Sandbox Escape via NodeVM10.0
- CVE-2026-92953vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray10.0
- CVE-2026-92954vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise8.6
Product normalization is registry-driven with AI assist and human review. How it works