FixVibe

// code / spotlight

vm2 Sandbox Breakout Advisory

A vulnerable JavaScript sandbox dependency can put untrusted-code boundaries at risk.

What it is

vm2 is commonly used where an app needs to evaluate JavaScript while limiting what that code can reach. When a vulnerable vm2 release is present, teams should treat the sandbox boundary as a patch priority, especially for tenant scripts, plugins, workflow expressions, or AI/tool-generated code.

How it happens

vm2 runs JavaScript inside a sandbox that is meant to keep that code away from the host process. CVE-2026-47208 is a sandbox breakout fixed in vm2 3.11.4: code running inside an affected sandbox can escape it and reach the Node.js process that hosts it.

What an attacker gets

If a deployed app runs untrusted code through an affected vm2 release, such as tenant scripts, plugins, workflow expressions, or AI-generated code, the sandbox stops being an isolation layer and that code can act with the host process's access to files, environment variables, and credentials.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `vm2` to 3.11.4 or newer, regenerate the active lockfile, rebuild the deployed Node.js runtime, and rerun the repo scan. If vm2 protects untrusted-code workflows, review queued inputs, tenant scripts, plugin data, logs, and credentials available to the Node.js process before treating the incident as closed.

// lance-le sur ta propre app

Continue de shipper pendant que FixVibe veille.

Connect a GitHub repo to check its code, dependencies and workflows.

Code source
198
tests dans cette catégorie
modules
155
vérifications code source dédiées
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// checks récents · correctifs pratiques · shippe sereinement

vm2 Sandbox Breakout Advisory: what it is and how to fix it · FixVibe