<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#vm2 NodeJS Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution - patch now]]></title><description><![CDATA[<p><a href="https://infosec.exchange/tags/vm2" rel="tag">#<span>vm2</span></a> NodeJS Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution - patch now!<br />Vm2 is used by 900+ <a href="https://infosec.exchange/tags/NPM" rel="tag">#<span>NPM</span></a> packages:<br /><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f447.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--point_down"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="👇"
      alt="👇"
    /></p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://thehackernews.com/2026/05/vm2-nodejs-library-vulnerabilities.html" title="vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution">
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGJE3Tcr425AIfztOUrdhPUiEkVY8bMrHMmO-5FZ2N3cLaW9ErdLJJS3KwjzYNvLAIcVT7xpSw8wswiDIPenyZa_ki3ZrOHJFY-cXKHPu0EGnfCGXxkEAlvE6tLogT8T_lRolQ-qI-GFqlgwqpbLD1HfmDo4HkJbV9XNDh9rcGbM3Nc8ruu5I_47DBmzsy/s1600/vm2.jpg" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://thehackernews.com/2026/05/vm2-nodejs-library-vulnerabilities.html">
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
</a>
</h5>
<p class="card-text line-clamp-3">12 vm2 flaws (CVSS up to 10.0) enable sandbox escape in ≤3.11.1, causing remote code execution risk; patched in 3.11.2.</p>
</div>
<a href="https://thehackernews.com/2026/05/vm2-nodejs-library-vulnerabilities.html" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQQyjwPYjJP0wddSEB8Dlpr3dlnQUs52-WmlrZfqJoBPeOvv2Zoqlq-FhEAz_Xeprj_mtrI1MGCW1JS840JUjVEK6VoNe6zCNNTw_7YmyvNmf3E5pprZ3zqP8lszq74Wt97SvbJo5yeuyep0U6-nGs0vdarg4_WUrc5r6L0ML0xE-BsPipJd2-1PMHTvO1/s32-e365/thn.jpg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />

















<p class="d-inline-block text-truncate mb-0">The Hacker News <span class="text-secondary">(thehackernews.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/2953dcb8-9366-43bb-94fd-b07f5e0d776c/vm2-nodejs-library-vulnerabilities-enable-sandbox-escape-and-arbitrary-code-execution-patch-now</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 07:10:09 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/2953dcb8-9366-43bb-94fd-b07f5e0d776c.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 May 2026 07:28:23 GMT</pubDate><ttl>60</ttl></channel></rss>