Description
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.
Published: 2026-09-17
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

vm2 before version 3.11.8 suffers from an incomplete fix to Error.cause sanitization, leaving sandbox‑escape capabilities when host‑wrapped AggregateError objects are caught during a single exception-handling traversal. Attackers can exploit a cycle‑detection bypass in the handleException routine to reach unsanitized host proxies stored in the error’s array, allowing them to execute arbitrary code within the sandbox and obtain sensitive process information. This flaw is a classic sandbox escape leading to full remote code execution, classified as CWE‑693.

Affected Systems

The only vendor explicitly identified is patriksimek providing the vm2 sandbox library. All versions prior to 3.11.8 are impacted. No other variants or vendor product lineages are listed.

Risk and Exploitability

The CVSS score of 9.5 indicates a high severity rating, and while the EPSS score is currently not available, the lack of a published mitigation elevates the exploitation risk. The flaw is not listed in the CISA KEV catalog, but the potential for complete remote code execution and process information disclosure means an attacker could gain full control of the host environment if the vulnerability is successfully leveraged. The likely attack vector involves malicious input into the vm2 sandbox that includes host‑wrapped AggregateError objects, a scenario that may arise from untrusted code execution or injection of crafted error structures. Given the high severity and clear path to control, the risk remains substantial.

Generated by OpenCVE AI on September 17, 2026 at 21:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.8 or later, which contains the fully patched Error.cause sanitization logic.
  • Ensure that any usage of AggregateError objects within the sandbox is sanitized or avoided; refrain from passing host‑wrapped errors into vm2 contexts.
  • Deploy monitoring and logging for sandbox activity to detect unexpected privilege escalation or process information leaks, and restrict exposure of host proxies in development and production environments.

Generated by OpenCVE AI on September 17, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x965-fc75-jpqh vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
History

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.
Title vm2 before 3.11.8 Sandbox Escape RCE via AggregateError
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:27:25.575Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92934

cve-icon Vulnrichment

Updated: 2026-09-17T14:27:15.442Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:57.513

Modified: 2026-09-17T15:17:00.520

Link: CVE-2026-92934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure