Vendor
The vm2 sandbox library is vulnerable to a sandbox breakout (CVE-2026-47698) due to insufficient validation of indirect calls, allowing attackers to execute arbitrary system commands on the host.