← Vulnerability feed

Vulnerability record · CVE-2022-36067 · published 6 September 2022

CVE-2022-36067: vm2 sandbox escape allows remote code execution on host

Vm2 Project · Vm2

vm2, a Node.js sandbox for running untrusted code with whitelisted built-in modules, fails to properly control dynamically-managed code, letting a threat actor bypass sandbox protections. Versions prior to 3.9.11 are affected, and the flaw is patched only in 3.9.11 with no known workarounds. Because vm2 is used specifically to contain untrusted code, a sandbox escape undermines the core security guarantee of any application relying on it.

10.0 CVSS 3.1 Critical EPSS 48% · top 1.2% CWE-913 · Improper control of dynamically-managed code
10.0CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication or interaction, scope change, and public exploit references make this a maximum-severity sandbox escape.

What it is

vm2, a Node.js sandbox for running untrusted code with whitelisted built-in modules, fails to properly control dynamically-managed code, letting a threat actor bypass sandbox protections. Versions prior to 3.9.11 are affected, and the flaw is patched only in 3.9.11 with no known workarounds. Because vm2 is used specifically to contain untrusted code, a sandbox escape undermines the core security guarantee of any application relying on it.

Impact

An attacker gains remote code execution on the host running the sandbox, escaping the isolation boundary and running arbitrary code with the privileges of the Node.js process. This can lead to full compromise of the host and any data or credentials it can reach.

Attack surface

The flaw is network-reachable (AV:N) with no privileges or user interaction required (PR:N/UI:N), meaning any path that feeds attacker-controlled code into the vm2 sandbox is a viable entry point. The scope change (S:C) reflects that the impact crosses from the sandbox into the host environment.

Exploitation

CVE-2022-36067 is not listed in CISA KEV, but EPSS is high at roughly 0.479 (98.8th percentile), and multiple references are tagged Exploit, including a public write-up, indicating exploit code and technical detail are publicly available.

What to do

  • Upgrade vm2 to version 3.9.11 or later; this is the only fix and there are no known workarounds.
  • If immediate upgrade is not possible, remove or disable vm2-based execution of untrusted code until patched.
  • Audit applications and dependencies that embed vm2 to confirm which instances run untrusted input and prioritize those for patching.
  • Run Node.js processes that use vm2 with least privilege and restrict outbound network and filesystem access to limit post-exploitation impact.
  • Track vendor advisories (for example NetApp) for downstream products that bundle the affected vm2 version.

Detection

  • Monitor for unexpected child processes, shell execution, or outbound connections spawned by Node.js processes that use vm2.
  • Alert on anomalous file writes or reads by Node.js service accounts outside expected application paths.
  • Review application logs for sandbox errors or unusual module loading patterns preceding suspicious process activity.
  • Inventory running Node.js services and check installed vm2 versions against 3.9.11 to find unpatched instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36067 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-44005Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and…EPSS 0.83%10.0CVE-2026-44006Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary…EPSS 0.77%10.0CVE-2026-43997Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Objec…EPSS 0.77%10.0CVE-2026-26332Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.…EPSS 0.74%10.0CVE-2026-22709Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitizatio…EPSS 1.3%10.0CVE-2023-37903Vm2 project vm2 os command injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to esc…EPSS 4.2%10.0CVE-2023-37466Vm2 project vm2 code injection vulnerabilityvm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of th…EPSS 3.9%10.0CVE-2023-32314Vm2 project vm2 injection vulnerabilityvm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and includ…EPSS 8.1%

Source: NIST National Vulnerability Database (record CVE-2022-36067), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.