← العودة للجدول
CVE-2026-47131
CVE-2026-47131 — GHSA: vm2 has a Sandbox Escape issue
📅 2026-05-29
🔴 Critical 🔥 No GHSA PoC Research Exploit CVSS 10

📋 الوصف الكامل

### Summary By combining `Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__")`, `Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__")`, and Node.js's `ERR_INVALID_ARG_TYPE` Error, the host's `TypeError` constructor can be obtained, which allows the escape from the sandbox. This allows attackers to run arbitrary code. ### PoC ```js "use strict";

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

PoC Research

🔗 CVE ID

CVE-2026-47131

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←