{
  "threat_severity" : "Important",
  "public_date" : "2026-05-13T17:31:54Z",
  "bugzilla" : {
    "description" : "vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution",
    "id" : "2477200",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2477200"
  },
  "cvss3" : {
    "cvss3_base_score" : "10.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-914",
  "details" : [ "vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.", "A flaw was found in vm2 (before 3.11.0). Sandboxed code can reach BaseHandler.getPrototypeOf to obtain arbitrary prototypes, enabling sandbox escape and arbitrary code execution. Fixed in 3.11.0." ],
  "statement" : "vm2 is vulnerable to sandbox escape via unrestricted access to BaseHandler.getPrototypeOf, allowing retrieval of arbitrary prototypes and host code execution. A remote unauthenticated attacker who can submit sandboxed code may escape the sandbox. Fixed in vm2 3.11.0.",
  "affected_release" : [ {
    "product_name" : "Red Hat Ansible Automation Platform 2.1",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50850",
    "cpe" : "cpe:/a:redhat:ansible_portal:2.1",
    "package" : "ansible-automation-platform/automation-portal:1785854226"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Developer Hub",
    "fix_state" : "Not affected",
    "package_name" : "rhdh/rhdh-hub-rhel9",
    "cpe" : "cpe:/a:redhat:rhdh:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-44006\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44006\nhttps://github.com/patriksimek/vm2/security/advisories/GHSA-qcp4-v2jj-fjx8" ],
  "name" : "CVE-2026-44006",
  "csaw" : false
}