Description
vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, and FinalizationRegistry and WeakRef are exposed to sandboxed code unmodified (they are not among the hardened globals in lib/setup-sandbox.js). Sandboxed code can register a FinalizationRegistry cleanup callback against an object and then drop the only strong reference to it; vm.run() returns within the configured timeout, but when the V8 garbage collector later reclaims the object it invokes the sandboxed cleanup callback outside any vm2 timeout accounting. A busy loop in that callback blocks the host event loop for an unbounded period, resulting in denial of service. The time of invocation depends on the garbage collector (e.g. under memory pressure or with --expose-gc).
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Timeout Bypass
Action: Immediate Patch
AI Analysis

Impact

vm2 before version 3.11.6 does not enforce the VM({ timeout }) option on code that runs outside the synchronous VM#run() call. The timeout wrapper only covers the single call to _runScript() and FinalizationRegistry and WeakRef are exposed to sandboxed code unchanged. A sandboxed script can register a cleanup callback with a FinalizationRegistry and then drop the only strong reference to the associated object. When V8 later reclaims the object, the registered callback is invoked outside any vm2 timeout accounting. If that callback contains a busy loop, it blocks the host event loop for an unlimited period, resulting in a denial‑of‑service. It is inferred that the attacker needs the ability to execute arbitrary code within the vm2 sandbox and must have a way to trigger garbage collection, either by allocating large objects or using the --expose‑gc flag.

Affected Systems

Vendors affected are those using the patriksimek vm2 package at or below version 3.11.6. The package is updated to 3.11.7 in a release that applies the timeout to all sandboxed code. No other vendors or products are listed in the CVE data.

Risk and Exploitability

The CVSS score of 8.7 signals a high‑severity flaw. Because the EPSS score is not available, the probability of exploitation cannot be quantified, but the vulnerability is reported as not listed in CISA KEV. It is inferred that the attacker must be able to execute arbitrary code within the vm2 sandbox and must have the capability to trigger garbage collection. The likely attack path involves an attacker providing malicious code to a vulnerable vm2 instance, registering a cleanup callback that loops indefinitely, and waiting for garbage collection to execute the callback outside the configured timeout, thereby blocking the host process.

Generated by OpenCVE AI on September 18, 2026 at 00:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the vm2 package to version 3.11.7 or newer, which enforces the timeout across all sandboxed code.
  • If an upgrade is not immediately possible, reconfigure the sandbox to exclude the FinalizationRegistry and WeakRef globals so that sandboxed scripts cannot register cleanup callbacks.
  • Apply defensive coding by avoiding infinite loops in any cleanup callbacks and monitor the event loop to detect long‑running operations.

Generated by OpenCVE AI on September 18, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r4fx-v8hh-22mv vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1100
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, and FinalizationRegistry and WeakRef are exposed to sandboxed code unmodified (they are not among the hardened globals in lib/setup-sandbox.js). Sandboxed code can register a FinalizationRegistry cleanup callback against an object and then drop the only strong reference to it; vm.run() returns within the configured timeout, but when the V8 garbage collector later reclaims the object it invokes the sandboxed cleanup callback outside any vm2 timeout accounting. A busy loop in that callback blocks the host event loop for an unbounded period, resulting in denial of service. The time of invocation depends on the garbage collector (e.g. under memory pressure or with --expose-gc).
Title vm2 before 3.11.7 Timeout Bypass via FinalizationRegistry
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:34:23.775Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92942

cve-icon Vulnrichment

Updated: 2026-09-18T19:33:31.335Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:59.467

Modified: 2026-09-18T20:17:30.843

Link: CVE-2026-92942

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T13:46:05Z

Links: CVE-2026-92942 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-1100

    Insufficient Isolation of System-Dependent Functions

  • CWE-400

    Uncontrolled Resource Consumption