REDHAT-BUG-2466508: High severity npm/vm2 vulnerability
Published May 4, 2026
·Updated
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
Affected Software
1 affected component
npm/vm2<3.11.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vm2to a version that resolves this vulnerability.Fixed in 3.11.0
Event History
May 4, 2026
Data Sourced
via Red Hat·07:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2466508?
The severity of REDHAT-BUG-2466508 is rated as high, with a score of 7.
2
How do I fix REDHAT-BUG-2466508?
To fix REDHAT-BUG-2466508, update your vm2 package to version 3.11.0 or later.
3
What issue does REDHAT-BUG-2466508 present?
REDHAT-BUG-2466508 allows attackers to escape the vm2 sandbox and execute arbitrary code.
4
Which software is affected by REDHAT-BUG-2466508?
The vulnerability REDHAT-BUG-2466508 affects the npm package vm2.
5
What version of vm2 is safe from REDHAT-BUG-2466508?
Version 3.11.0 of vm2 is safe from the vulnerability REDHAT-BUG-2466508.