What is CVE-2026-47686?
This vulnerability exists in the vm2 sandbox for Node.js. The handleException() function fails to sanitize Error.cause, allowing sandbox code to access powerful host objects like process. Upgrading to version 3.11.6 is recommended.
Azərbaycanca: Bu boşluq Node.js üçün vm2 sandbox mühitində aşkarlanıb. handleException() funksiyası Error.cause-u sanitizə etmədiyi üçün sandbox daxilindəki kod `process` kimi güclü host obyektinə çıxış əldə edə bilər. vm2-ni 3.11.6 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which product is affected by CVE-2026-47686?
This vulnerability exists in the vm2 sandbox for Node.js.
How can I protect against CVE-2026-47686?
Upgrading to version 3.11.6 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.