THREAT OPS › Threat News › [NVD] CVE-2026-44008 (CRITICAL 9.8) — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to
[NVD] CVE-2026-44008 (CRITICAL 9.8) — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to
CVE-2026-44008 CVSS: 9.8 CRITICAL Published: 2026-05-13T18:16:17.667
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Function object.
Indicators of compromise
- CVE-2026-44008cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44008