Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-92944: vm2 can run unauthorized code via Promise trick

CVE-2026-92944 · published 23 days ago
Summary

The vm2 sandbox library for Node.js can be bypassed using a special async function that tricks its protection. This lets an attacker run code on the host system. Upgrade vm2 to the latest version or apply the vendor's patch to close the gap.

What to do
  • Update vm2 to version 3.11.7.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 >= 3.10.2, <= 3.11.6
Fix: upgrade to 3.11.7
Original advisory text
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.species, allowing them to reach the host Function constructor and process object for arbitrary code execution.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92944 · MITRE
Track software like this
Free during beta