CVE-2026-22709 | patriksimek vm2 up to 3.10.1 lib/setup-sandbox.js code injection (GHSA-99p7-6v5w-7xg8 / EUVD-2026-4660)
A vulnerability was found in patriksimek vm2 up to 3.10.1. It has been rated as critical. The affected element is an unknown function in the library lib/setup-sandbox.js. Performing a manipulation results in code injection.
This vulnerability is cataloged as CVE-2026-22709. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.