CVE-2026-47210 - vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
CVE ID :CVE-2026-47210 Published : June 12, 2026, 3:16 p.m. | 1 hour, 51 minutes ago Description :vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed...