CVE-2026-45411

CRITICAL

CVSS v3.1: 9.8 · EPSS: 0.0045 (36.2 percentile)

NetworkNo privilegesNo user interactionVendor advisory ref

Source data as of:

At a glance

Severity
CRITICAL
CVSS
9.8 v3.1 · NVD
EPSS
0.0045 (36.2 percentile) · FIRST.org
CISA KEV
No
Attack conditions (CVSS vector)
NetworkNo privilegesNo user interaction · Source: NVD Vector
Affected vendors
vm2_project
Published
2026-05-13 · Modified: 2026-06-30

CVSS / EPSS / KEV

CVSS v3.1 9.8 / 10 CRITICAL Source: NVD
EPSS 0.0045 36.2 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed to the yield* iterator as the next value. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fixed in 3.11.3.

Record details

CVE ID
CVE-2026-45411
CVSS (v3.1)
9.8 (CRITICAL)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
3.9
Impact subscore
5.9
EPSS
0.0045 (36.2 percentile) — 2026-06-30
CISA KEV
No
Weakness (CWE)
CWE-668, CWE-237
Affected vendors
vm2_project
Affected configurations (CPE)
1
Published
2026-05-13
Modified
2026-06-30
Status
Modified

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.