← Back to browse · API

CVE-2026-44006

Severity
CRITICAL
CVSS
10.0
EPSS
0.00815
Risk score
40.29
CISA KEV
No
PoC
No
Published
2026-05-13
Modified
2026-08-06
First seen
2026-08-07
Aliases
EUVD-2026-30076, GHSA-QCP4-V2JJ-FJX8
Products
patriksimek:vm2 < 3.11.0, vm2_project:vm2
Sources
nvd CVE-2026-44006
euvd EUVD-2026-30076

Description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

References