THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-44008 (CRITICAL 9.8) — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to

[NVD] CVE-2026-44008 (CRITICAL 9.8) — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to

lownvdPublished 2026-05-13

CVE-2026-44008 CVSS: 9.8 CRITICAL Published: 2026-05-13T18:16:17.667

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Function object.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44008