#VU122009 Code Injection in vm2 - CVE-2026-22709
Published: January 26, 2026
vm2
Patrik Simek
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the "Promise.prototype.then" and "Promise.prototype.catch" callback sanitization can be bypassed. A remote attacker can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.