vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
vm2 is a popular Node.js sandboxing library designed to safely execute untrusted code in isolated virtual machine contexts. Version 3.10.4 contains a critical vulnerability that allows attackers to completely escape the sandbox and execute arbitrary commands on the host system with zero user interaction required. This affects any application using vm2 to run user-supplied or third-party code—including educational platforms, code execution services, containerized environments, and security testing tools. The CVSS 9.8 critical rating reflects the complete loss of sandbox integrity and the ability to compromise the entire host process.
While this CVE maps to CWE-693 (Protection Mechanism Failure), Casky's extended reasoning capabilities would identify the underlying attack patterns associated with sandbox escape techniques that typically correlate with MITRE ATT&CK tactics like Execution (T1059) and Privilege Escalation (T1548). Practitioners using Casky would receive findings highlighting anomalous object access patterns within VM contexts, unexpected host process interactions from sandboxed code, and behavioral signatures indicating escape attempts—such as prototype chain manipulation or host object access. The 0 matching skills reflects that this specific vm2 flaw requires version-specific indicators; however, Casky's AI-driven analysis would flag the class of vulnerabilities (sandbox breakout patterns) during threat hunting activities, allowing security teams to identify affected deployments and prioritize patching to version 3.10.5.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-26956. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation