ZeroHour

CVE-2026-44006

PoC
CVSS 3.1
10.0 critical
EPSS
<1%p55
Published
()
Modified
Description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

Vendors
vm2 project
Products
vm2
Weakness
CWE-94, CWE-914
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news