CVE-2026-24120
Critical · CVSS 9.8vm2 — Sandbox Escape / Arbitrary Code Execution (bypass of CVE-2023-37466 fix)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-94, CWE-693, CWE-807
Description
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.10.5.
Search profile — drives PoC discovery
Symbols vm2VM2sandboxpatriksimekCVE-2023-37466GHSA-qvjj-29qf-hp7p3.10.5escapehost
Keywords CVE-2026-24120vm2 sandbox escapevm2 bypassvm2 RCEvm2 3.10.5CVE-2023-37466 bypassGHSA-qvjj-29qf-hp7pvm2 arbitrary command executionvm2 Node.js sandbox escape PoCpatriksimek vm2 exploit
Versions: < 3.10.5
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://github.com/patriksimek/vm2/releases/tag/v3.10.5
- https://github.com/patriksimek/vm2/security/advisories/GHSA-qvjj-29qf-hp7p
- https://access.redhat.com/security/cve/CVE-2026-24120
- https://bugzilla.redhat.com/show_bug.cgi?id=2466529
- https://github.com/patriksimek/vm2/security/advisories/GHSA-qvjj-29qf-hp7p
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24120.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z