CRITICALCVSS 9.8Vulnerability

CVE-2026-45411

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed to the yield* iterator as the next value. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fixed in 3.11.3.

Properties

summary
vm2 Has a Sandbox Breakout Using Async Generator
severity
CRITICAL
epss_score
0.00568
cvss_score
9.8
ghsa_published
2026-05-14T21:14:32Z
source_url
https://github.com/advisories/GHSA-248r-7h7q-cr24
ghsa_updated
2026-05-14T21:14:35Z
ghsa_id
GHSA-248r-7h7q-cr24
score
9.8
cve_id
CVE-2026-45411
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-05-13T18:16:19.427
last_modified
2026-08-06T13:18:16.193
epss_percentile
0.44131

Related Entities (8)

HAS_WEAKNESS (2)

[Weakness]
[Weakness]Exposure of Resource to Wrong Sphere

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/vm2

AFFECTS (1)

[Software]npm/vm2

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-45411 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal