CVE-2026-44009: VM2 Project VM2
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
Affected products
- VM2 Project VM2: before 3.11.2 (fixed in 3.11.2)
Published 2026-05-13. Last modified 2026-09-07.