← العودة للجدول
CVE-2026-47131
CVE-2026-47131 — vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combin
📅 2026-06-12
🔴 Critical 🔥 No NVD Exploit Vulnerability CVSS 10

📋 الوصف الكامل

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained, which allows the escape from the sandbox. This allows attackers to run arb

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-47131

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.11.4

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←