{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44007.json"
      }
    ],
    "title": "vm2: vm2: Arbitrary code execution via nested NodeVM bypass",
    "tracking": {
      "current_release_date": "2026-08-05T18:22:16+00:00",
      "generator": {
        "date": "2026-08-05T18:22:16+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.12"
        }
      },
      "id": "CVE-2026-44007",
      "initial_release_date": "2026-05-13T17:33:19.799000+00:00",
      "revision_history": [
        {
          "date": "2026-05-13T17:33:19.799000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-21T07:13:56+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-05T18:22:16+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Developer Hub",
                "product": {
                  "name": "Red Hat Developer Hub",
                  "product_id": "red_hat_developer_hub",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:rhdh:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Developer Hub"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Ansible Automation Platform 2.1",
                "product": {
                  "name": "Red Hat Ansible Automation Platform 2.1",
                  "product_id": "Red Hat Ansible Automation Platform 2.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ansible_portal:2.1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Ansible Automation Platform"
          },
          {
            "category": "product_version",
            "name": "rhdh/rhdh-hub-rhel9",
            "product": {
              "name": "rhdh/rhdh-hub-rhel9",
              "product_id": "rhdh/rhdh-hub-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/rhdh-hub-rhel9?repository_url=registry.redhat.io/rhdh/rhdh-hub-rhel9"
              }
            }
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
                "product": {
                  "name": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
                  "product_id": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/automation-portal@sha256%3Aa85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d?arch=amd64&repository_url=registry.redhat.io/ansible-automation-platform/automation-portal&tag=1785854226"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64 as a component of Red Hat Ansible Automation Platform 2.1",
          "product_id": "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64"
        },
        "product_reference": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
        "relates_to_product_reference": "Red Hat Ansible Automation Platform 2.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub",
          "product_id": "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
        },
        "product_reference": "rhdh/rhdh-hub-rhel9",
        "relates_to_product_reference": "red_hat_developer_hub"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-44007",
      "cwe": {
        "id": "CWE-1100",
        "name": "Insufficient Isolation of System-Dependent Functions"
      },
      "discovery_date": "2026-05-13T18:01:46.215400+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2477198"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in vm2 (before 3.11.1). With nesting: true, sandbox code can require('vm2') regardless of outer require settings (including require: false), spawn an inner NodeVM with unrestricted require, and execute arbitrary OS commands on the host. Fixed in 3.11.1.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "vm2: vm2: Arbitrary code execution via nested NodeVM bypass",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "vm2 NodeVM is vulnerable to sandbox escape when nesting is enabled, allowing unconditional require of vm2 and creation of an unrestricted inner NodeVM. An attacker with low privileges who can run code in a nested NodeVM may execute arbitrary OS commands on the host. Fixed in vm2 3.11.1.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64"
        ],
        "known_not_affected": [
          "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-44007"
        },
        {
          "category": "external",
          "summary": "RHBZ#2477198",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477198"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-44007",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44007"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-44007",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44007"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/05/11",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/05/11"
        },
        {
          "category": "external",
          "summary": "https://github.com/patriksimek/vm2/security/advisories/GHSA-8hg8-63c5-gwmx",
          "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-8hg8-63c5-gwmx"
        }
      ],
      "release_date": "2026-05-13T17:33:19.799000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-05T16:35:19+00:00",
          "details": "For more about Ansible plugins for Red Hat Developer Hub, see References links",
          "product_ids": [
            "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:50850"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
          ]
        }
      ],
      "title": "vm2: vm2: Arbitrary code execution via nested NodeVM bypass"
    }
  ]
}