This advisory has been withdrawn because it is a duplicate of GHSA-88hf-g992-jg85. This link is maintained to preserve external references.
vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host proto getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.
{
"cwe_ids": [
"CWE-913"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T22:46:58Z",
"nvd_published_at": "2026-09-17T14:18:01Z",
"severity": "CRITICAL"
}