CVE-2026-47698 | patriksimek vm2 up to 3.11.5 Sandbox lib/bridge.js Function.prototype.call privileges management
A vulnerability was found in patriksimek vm2 up to 3.11.5 and classified as critical. This impacts the function Function.prototype.call of the file lib/bridge.js of the component Sandbox. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-47698. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More