REDHAT-BUG-2466548: High severity vm2 vm2 vulnerability
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vm2to a version that resolves this vulnerability.Fixed in 3.10.5
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2466548?
The severity of REDHAT-BUG-2466548 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2466548?
To fix REDHAT-BUG-2466548, upgrade to vm2 version 3.10.5 or later.
What are the implications of REDHAT-BUG-2466548?
The implications of REDHAT-BUG-2466548 include potential full sandbox escape allowing attackers to execute arbitrary code on the host system.
What software is affected by REDHAT-BUG-2466548?
The software affected by REDHAT-BUG-2466548 is vm2 version 3.10.4.
When was REDHAT-BUG-2466548 published?
REDHAT-BUG-2466548 was published on May 4, 2026.