CVE-2026-44001 - Vulnerability Analysis
HighCVSS: 8.6Last Updated: May 14, 2026
vm2 - Denial of Service
Published: May 13, 2026Updated: May 14, 2026PoC AvailableRemote Exploitable
Overview
vm2 < 3.11.0 contains a sandbox escape vulnerability caused by unhandled Promise rejection propagation from sandboxed code to the host Node.js process, letting attackers crash the host process, exploit requires executing sandboxed code.
Severity & Score
Severity: High
CVSS Score: 8.6
Impact
Attackers can crash the host Node.js process, causing denial of service.
Mitigation
Update to version 3.11.0 or later.
Related Resources
Details
- CVE ID
- CVE-2026-44001
- Severity
- High
- CVSS Score
- 8.6
- Type
- sandbox_escape
- Status
- confirmed
CWE
- CWE-248
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H