FixVibe

// 코드 / 스포트라이트

vm2 Sandbox Breakout Advisory

A vulnerable JavaScript sandbox dependency can put untrusted-code boundaries at risk.

What it is

vm2 is commonly used where an app needs to evaluate JavaScript while limiting what that code can reach. When a vulnerable vm2 release is present, teams should treat the sandbox boundary as a patch priority, especially for tenant scripts, plugins, workflow expressions, or AI/tool-generated code.

How it happens

vm2 runs JavaScript inside a sandbox that is meant to keep that code away from the host process. CVE-2026-47208 is a sandbox breakout fixed in vm2 3.11.4: code running inside an affected sandbox can escape it and reach the Node.js process that hosts it.

What an attacker gets

If a deployed app runs untrusted code through an affected vm2 release, such as tenant scripts, plugins, workflow expressions, or AI-generated code, the sandbox stops being an isolation layer and that code can act with the host process's access to files, environment variables, and credentials.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `vm2` to 3.11.4 or newer, regenerate the active lockfile, rebuild the deployed Node.js runtime, and rerun the repo scan. If vm2 protects untrusted-code workflows, review queued inputs, tenant scripts, plugin data, logs, and credentials available to the Node.js process before treating the incident as closed.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Connect a GitHub repo to check its code, dependencies and workflows.

소스 코드
198
이 카테고리에서 실행되는 테스트
모듈
155
전용 소스 코드 검사
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

vm2 Sandbox Breakout Advisory: what it is and how to fix it · FixVibe