Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-92937: vm2 may let sandbox code run commands on host

CVE-2026-92937 · published 23 days ago
Summary

The vm2 library version 3.11.6 does not fully block a way for code running inside its sandbox to reach the underlying Node.js process. An attacker can craft a rejected Promise that bypasses the safety check and gain access to host objects, allowing them to execute arbitrary commands. Upgrade to vm2 version 3.11.7 or later to close this gap.

What to do
  • Update vm2 to version 3.11.7.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 3.11.6
Fix: upgrade to 3.11.7
Original advisory text
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.g., p.then.call(p, undefined, cb)) makes the intercepted target host Function.prototype.call, so the sanitiser never runs and the raw host error reaches sandbox code with its own properties intact. If an embedder exposes a host-realm Promise to the sandbox (an async host function bridged via the sandbox option, or a NodeVM external module's async method) and that Promise rejects with an Error carrying a non-primitive own property referencing a host object (for example err.detail = process), untrusted code in the sandbox obtains a fully functional proxy to that host object and can execute arbitrary commands with the privileges of the host process (e.g., e.detail.mainModule.require('child_process').execSync(...)). The direct p.then(undefined, cb), bind, and Reflect.apply forms are correctly sanitised. Fixed in vm2 3.11.7.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
1% chance of attack within 30 days
Type
CWE-94Code Injection
CWE-693Protection Mechanism Failure
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92937 · MITRE
Track software like this
Free during beta