REDHAT-BUG-2477185: High severity npm/vm2 vulnerability
Published May 13, 2026
·Updated
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
Affected Software
1 affected component
npm/vm2<3.11.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vm2to a version that resolves this vulnerability.Fixed in 3.11.2
Event History
May 13, 2026
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2477185?
The severity of REDHAT-BUG-2477185 is classified as high with a score of 7.
2
How do I fix REDHAT-BUG-2477185?
To fix REDHAT-BUG-2477185, you need to upgrade vm2 to version 3.11.2 or later.
3
What software is affected by REDHAT-BUG-2477185?
The affected software is npm/vm2, specifically versions prior to 3.11.2.
4
When was REDHAT-BUG-2477185 published?
REDHAT-BUG-2477185 was published on May 13, 2026.
5
Is there a known mitigation for REDHAT-BUG-2477185?
The only known mitigation for REDHAT-BUG-2477185 is to upgrade to vm2 version 3.11.2 or later.