REDHAT-BUG-2477200: High severity vm2 vm2 vulnerability
Published May 13, 2026
·Updated
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
Affected Software
1 affected component
vm2 vm2<3.11.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vm2to a version that resolves this vulnerability.Fixed in 3.11.0
Event History
May 13, 2026
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2477200?
The severity of REDHAT-BUG-2477200 is high with a rating of 7.
2
How do I fix REDHAT-BUG-2477200?
To fix REDHAT-BUG-2477200, upgrade vm2 to version 3.11.0 or later.
3
What is the impact of REDHAT-BUG-2477200?
The impact of REDHAT-BUG-2477200 allows attackers to access arbitrary prototypes through BaseHandler.getPrototypeOf.
4
Which versions of vm2 are affected by REDHAT-BUG-2477200?
Versions of vm2 prior to 3.11.0 are affected by REDHAT-BUG-2477200.
5
When was REDHAT-BUG-2477200 published?
REDHAT-BUG-2477200 was published on May 13, 2026.