CVE-2026-43999
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module.load(), which loads any module by name directly in the host context, completely bypassing vm2's builtin restriction. This allows sandboxed code to load excluded builtins like childprocess and achieve remote code execution. This vulnerability is fixed in 3.11.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43999.json, https://access.redhat.com/errata/RHSA-2026:50850, https://access.redhat.com/security/cve/CVE-2026-43999, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43999.json, https://github.com/patriksimek/vm2/security/advisories/GHSA-947f-4v7f-x2v8, https://nvd.nist.gov/vuln/detail/CVE-2026-43999, https://bugzilla.redhat.com/show_bug.cgi?id=2477196