Vulnerability Description
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained, which allows the escape from the sandbox. This allows attackers to run arbitrary code. This issue has been patched in version 3.11.4.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/patriksimek/vm2/commit/27c525f4615e2b983f122e2bed327d810126f5
- https://github.com/patriksimek/vm2/releases/tag/v3.11.4
- https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg
- https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg
FAQ
What is CVE-2026-47131?
CVE-2026-47131 is a vulnerability with a CVSS score of 10.0 (CRITICAL). vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__...
How severe is CVE-2026-47131?
CVE-2026-47131 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-47131?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.