Description
vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.g., p.then.call(p, undefined, cb)) makes the intercepted target host Function.prototype.call, so the sanitiser never runs and the raw host error reaches sandbox code with its own properties intact. If an embedder exposes a host-realm Promise to the sandbox (an async host function bridged via the sandbox option, or a NodeVM external module's async method) and that Promise rejects with an Error carrying a non-primitive own property referencing a host object (for example err.detail = process), untrusted code in the sandbox obtains a fully functional proxy to that host object and can execute arbitrary commands with the privileges of the host process (e.g., e.detail.mainModule.require('child_process').execSync(...)). The direct p.then(undefined, cb), bind, and Reflect.apply forms are correctly sanitised. Fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 10 Critical
EPSS: 1.0% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A sandbox escape flaw in vm2 allows an attacker to execute arbitrary code in the host Node.js process. The vulnerability arises when a host Promise that contains a rejected error with non‑primitive properties is routed through a proxy indirection (e.g., Function.prototype.call or .apply). The sanitization logic misidentifies the target as a host call, permitting the raw host error—including attached host objects such as process—to leak into untrusted sandbox code. The attacker can then use these objects to invoke child process execution or other privileged operations. This flaw is classified under CWE-94, code injection and runtime code execution.

Affected Systems

The affected product is vm2 v3.11.6, maintained by patriksimek. The issue exists only in that specific release; support exists in later versions, with v3.11.7 and beyond incorporating the fix.

Risk and Exploitability

The CVSS score is 10, indicating a critical severity. EPSS data is not available, leaving the exploit probability uncertain, and the vulnerability is not yet listed in CISA KEV. The likely attack vector requires the embedder to expose a host‑realm Promise to the sandbox, typically through the sandbox option or an external module’s async method. If this condition is met, the exploit is straightforward: trigger a rejected Promise with an Error that carries a host object reference, then the sandbox code obtains a proxy to that host object and invokes methods such as require('child_process').execSync, achieving remote code execution with host privileges.

Generated by OpenCVE AI on September 17, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later to apply the vendor patch addressing the Promise sanitization flaw.
  • If the upgrade cannot be applied immediately, configure the sandbox to avoid exposing host‑realm Promises; disable the sandbox option or ensure that async host functions are not bridged into the sandbox environment.
  • Remove or restrict any external modules that expose asynchronous host methods to the sandbox, or replace them with synchronous alternatives that do not carry user‑controlled error objects into the protected context.

Generated by OpenCVE AI on September 17, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-647f-g98j-qq25 vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.g., p.then.call(p, undefined, cb)) makes the intercepted target host Function.prototype.call, so the sanitiser never runs and the raw host error reaches sandbox code with its own properties intact. If an embedder exposes a host-realm Promise to the sandbox (an async host function bridged via the sandbox option, or a NodeVM external module's async method) and that Promise rejects with an Error carrying a non-primitive own property referencing a host object (for example err.detail = process), untrusted code in the sandbox obtains a fully functional proxy to that host object and can execute arbitrary commands with the privileges of the host process (e.g., e.detail.mainModule.require('child_process').execSync(...)). The direct p.then(undefined, cb), bind, and Reflect.apply forms are correctly sanitised. Fixed in vm2 3.11.7.
Title vm2 3.11.6 Remote Code Execution via Promise call/apply
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:25:51.435Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92937

cve-icon Vulnrichment

Updated: 2026-09-18T19:25:17.174Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:58.517

Modified: 2026-09-18T20:17:30.707

Link: CVE-2026-92937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')