Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-92934: vm2 library can let attackers run code on host

CVE-2026-92934 · published 24 days ago
Summary

The vm2 JavaScript sandbox library, used to keep code isolated, has a flaw that can allow a malicious script to break out of its safe area and run on the main system. This could let an attacker execute any command and see process details. Upgrade vm2 to version 3.11.8 or newer, or apply the provided fix, to close the gap.

What to do
  • Update vm2 to version 3.11.8.
  • Update patriksimek vm2 to version 3.11.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.8
npm – vm2 <= 3.11.7
< 3.11.8
Fix: upgrade to 3.11.8
Original advisory text
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.5 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Sep 2026
Updated11 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta