CVE-2026-44009: VM2 Project VM2

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

Affected products

Published 2026-05-13. Last modified 2026-09-07.