Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-92954: vm2 sandbox can let rejected Promise crash host

CVE-2026-92954 · published 23 days ago
Summary

When using vm2 version 3.10.0 through 3.11.7, code run inside the sandbox can call a host function that returns a rejected Promise and ignore the result. This leaves the Promise unhandled, causing Node.js to shut down the entire application. Upgrade vm2 to version 3.11.8 or later to prevent this behavior.

What to do
  • Update vm2 to version 3.11.8.
  • Update patriksimek vm2 to version 3.11.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.8
npm – vm2 >= 3.10.0, <= 3.11.7
>= 3.10.0, < 3.11.8
Fix: upgrade to 3.11.8
Original advisory text
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs host-side rejection sanitizers when sandbox code calls .then/.catch/.finally. As a result, code running in the sandbox can invoke a host function that returns a rejected Promise (for example events.once() exposed via the NodeVM events builtin, or any embedder-provided Promise-returning API) and simply ignore the return value, leaving the host Promise unhandled so that Node.js's default unhandled-rejection behavior terminates the host process. This is an incomplete fix of GHSA-hw58-p9xv-2mjh. The issue is fixed in version 3.11.8.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-248Uncaught Exception
CWE-703Improper Check or Handling of Exceptional Conditions
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta