Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-92934: vm2 library can let attackers run code on host
CVE-2026-92934 · published 24 days ago
Summary
The vm2 JavaScript sandbox library, used to keep code isolated, has a flaw that can allow a malicious script to break out of its safe area and run on the main system. This could let an attacker execute any command and see process details. Upgrade vm2 to version 3.11.8 or newer, or apply the provided fix, to close the gap.
What to do
- Update vm2 to version 3.11.8.
- Update patriksimek vm2 to version 3.11.8 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.8 |
| npm | – | vm2 |
<= 3.11.7 < 3.11.8 Fix: upgrade to 3.11.8
|
Original advisory text
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.
References
- https://www.vulncheck.com/advisories/vm2-before-3.11.8-sandbox-escape-rce-via-ag...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92934... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92934 Vendor Advisory
- https://github.com/patriksimek/vm2/security/advisories/GHSA-x965-fc75-jpqh
- https://github.com/patriksimek/vm2/commit/c8c232530b860cfecf6f94bc8d0d0890aa3814... URL
- https://github.com/patriksimek/vm2/releases/tag/v3.11.8 URL
- https://github.com/advisories/GHSA-x965-fc75-jpqh
- https://github.com/patriksimek/vm2 Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.5
Critical
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Sep 2026
Updated11 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92934 · NVD
CVE-2026-92934 · MITRE
CVE-2026-92934 · OSV
GHSA-x965-fc75-jpqh · GHSA
GHSA-x965-fc75-jpqh · OSV
Track software like this
Free during beta