CVE-2026-44006
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44006.json, https://access.redhat.com/errata/RHSA-2026:50850, https://access.redhat.com/security/cve/CVE-2026-44006, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44006.json, https://github.com/patriksimek/vm2/security/advisories/GHSA-qcp4-v2jj-fjx8, https://nvd.nist.gov/vuln/detail/CVE-2026-44006, https://bugzilla.redhat.com/show_bug.cgi?id=2477200