← العودة للجدول
CVE-2026-47208
CVE-2026-47208 — GHSA: vm2 is Vulnerable to Sandbox Breakout Through Promise Species
📅 2026-05-29
🔴 Critical 🔥 No GHSA PoC Research Exploit CVSS 10

📋 الوصف الكامل

### Summary VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. ### Details The `localPromise` constructor was changed to call `this.then(undefined, eater)` to ensure a rejected promise is always used. However, this is missing a call to `resetPromiseSpecies` to ensure that

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

PoC Research

🔗 CVE ID

CVE-2026-47208

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←