FixVibe

// 代码 / 聚焦

vm2 Sandbox Breakout Advisory

A vulnerable JavaScript sandbox dependency can put untrusted-code boundaries at risk.

What it is

vm2 is commonly used where an app needs to evaluate JavaScript while limiting what that code can reach. When a vulnerable vm2 release is present, teams should treat the sandbox boundary as a patch priority, especially for tenant scripts, plugins, workflow expressions, or AI/tool-generated code.

How it happens

vm2 runs JavaScript inside a sandbox that is meant to keep that code away from the host process. CVE-2026-47208 is a sandbox breakout fixed in vm2 3.11.4: code running inside an affected sandbox can escape it and reach the Node.js process that hosts it.

What an attacker gets

If a deployed app runs untrusted code through an affected vm2 release, such as tenant scripts, plugins, workflow expressions, or AI-generated code, the sandbox stops being an isolation layer and that code can act with the host process's access to files, environment variables, and credentials.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `vm2` to 3.11.4 or newer, regenerate the active lockfile, rebuild the deployed Node.js runtime, and rerun the repo scan. If vm2 protects untrusted-code workflows, review queued inputs, tenant scripts, plugin data, logs, and credentials available to the Node.js process before treating the incident as closed.

// 在你自己的應用上跑一遍

放心继續發布,FixVibe 持續幫你看守風险。

Connect a GitHub repo to check its code, dependencies and workflows.

源代码
198
本類别中触發的测試
模塊
155
專属 源代码 检查
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 最新检查 · 实用修複 · 安心發布

vm2 Sandbox Breakout Advisory: what it is and how to fix it · FixVibe