Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-93606: vm2 sandbox can be escaped to run host code
CVE-2026-93606 · published 22 days ago
Summary
Versions of the vm2 package prior to 3.12.1 allow code running inside its sandbox to break out and interact directly with the host system. If the sandbox is given a host function that returns a promise, an attacker can manipulate that promise to gain control of host objects and potentially execute arbitrary commands. Update vm2 to version 3.12.1 or later to close this gap.
What to do
- Update patriksimek vm2 to version 3.12.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| patriksimek | vm2 | < 3.12.1 |
Original advisory text
vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`.then` neutralization is installed only on the sandbox intrinsic `Promise.prototype`, so it never applies to a host Promise. Code running inside the sandbox can overwrite `p.constructor[Symbol.species]` on the host Promise and then call `p.then()` with no `onRejected` handler; V8 substitutes its internal Thrower, which re-throws the raw host rejection value into a resolve/reject closure captured by the attacker. This delivers an unsanitized, fully functional bridge proxy of the host object to sandboxed code, bypassing handleException and hostPromiseSanitizeReject. If the rejection value is host-pivotable (for example a host `process` object), this results in arbitrary code execution on the host. Fixed in 3.12.1.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93606... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-93606 Vendor Advisory
- https://www.vulncheck.com/advisories/vm2-before-3.12.1-sandbox-escape-via-promis...
- https://github.com/patriksimek/vm2/security/advisories/GHSA-6454-5x88-m6jw
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-693Protection Mechanism Failure
Timeline
Published18 Sep 2026
Updated7 Oct 2026
First seen18 Sep 2026
Track software like this
Free during beta