CVE-2026-44009: vm2 has Sandbox Breakout Through Null Proto Exception

Severity: Critical

CVSS Score: 9.8

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.