Dependency scanning
Check whether vm2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-92963
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
CVE-2026-92961
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
CVE-2026-92962
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter
CVE-2026-92960
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
CVE-2023-32314
vm2 Sandbox Escape vulnerability
CVE-2023-32313
vm2 vulnerable to Inspect Manipulation
CVE-2023-29017
vm2 vulnerable to sandbox escape
CVE-2019-10761
vm2 before 3.6.11 vulnerable to sandbox escape
CVE-2026-47683
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
CVE-2026-47686
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
CVE-2026-47698
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
CVE-2026-47137
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
CVE-2023-37903
vm2 Sandbox Escape vulnerability
CVE-2021-23555
Sandbox bypass in vm2
CVE-2021-23449
Prototype Pollution in vm2
CVE-2026-26956
VM2 Has a WASM Sandbox Escape
CVE-2026-47140
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
CVE-2026-47131
vm2 has a Sandbox Escape issue
CVE-2026-47210
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
CVE-2026-47208
vm2 is Vulnerable to Sandbox Breakout Through Promise Species
CVE-2026-47209
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
CVE-2026-47135
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
CVE-2026-47139
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
CVE-2026-47141
NodeVM observability builtins leak host process and HTTP request data
CVE-2026-45411
vm2 Has a Sandbox Breakout Using Async Generator
CVE-2026-44002
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
CVE-2026-44003
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
CVE-2026-44006
vm2 has a Sandbox Escape Vulnerability
CVE-2026-44001
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
CVE-2026-44005
vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
CVE-2026-44000
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
CVE-2026-43998
vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
CVE-2026-44007
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
CVE-2026-44009
vm2 has Sandbox Breakout Through Null Proto Exception
CVE-2026-44008
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
CVE-2026-43999
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
CVE-2026-44004
vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
CVE-2026-43997
vm2 Access to Host Object Enables Sandbox Escape
CVE-2026-24118
VM2 Sandbox Breakout Through __lookupGetter__
CVE-2026-24781
VM2 Has Sandbox Breakout Through Inspect Function
CVE-2026-26332
VM2 Has a Sandbox Escape Issue via SuppressedError
CVE-2026-24120
VM2 Has Sandbox Breakout Through Promise Species
CVE-2023-37466
vm2 Sandbox Escape vulnerability
CVE-2026-22709
vm2 has a Sandbox Escape
CVE-2023-30547
vm2 Sandbox Escape vulnerability
CVE-2023-29199
vm2 Sandbox Escape vulnerability
CVE-2022-36067
vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host
CVE-2022-25893
vm2 vulnerable to Arbitrary Code Execution
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes