{
  "threat_severity" : "Important",
  "public_date" : "2026-05-04T16:33:32Z",
  "bugzilla" : {
    "description" : "vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function",
    "id" : "2466531",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2466531"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-653",
  "details" : [ "vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.", "A flaw was found in vm2, an open-source virtual machine (VM) sandbox for Node.js. This vulnerability allows an attacker to escape the sandbox environment by exploiting the `inspect` function. Successful exploitation can lead to arbitrary code execution on the host system, compromising the integrity and confidentiality of the system." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Developer Hub 1.9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26234",
    "cpe" : "cpe:/a:redhat:rhdh:1.9::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1781187342"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Developer Hub",
    "fix_state" : "Will not fix",
    "package_name" : "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
    "cpe" : "cpe:/a:redhat:rhdh:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-24781\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24781\nhttps://github.com/patriksimek/vm2/commit/8d30d93213c1898b3e035298b89a814970dd1189\nhttps://github.com/patriksimek/vm2/commit/bdd3d15e57bc4ec5e70365cd79f7cb0256e5f88c\nhttps://github.com/patriksimek/vm2/commit/fd266d084e0a3322d0f71ba2a8dc4c96cd030228\nhttps://github.com/patriksimek/vm2/releases/tag/v3.11.0\nhttps://github.com/patriksimek/vm2/security/advisories/GHSA-v37h-5mfm-c47c" ],
  "name" : "CVE-2026-24781",
  "csaw" : false
}