Impact
The vulnerability in vm2 permits a sandbox escape that results in arbitrary code execution. When Promise.prototype.finally is invoked, the sandbox’s wrapper protections are bypassed due to a stale PromiseThenLookupChain protector in V8 14.6, which is bundled in Node.js 26. By crafting an async function that returns a Promise whose Symbol.species points to an attacker‑controlled constructor, an attacker can obtain the host Function constructor and the process object, enabling execution of malicious code.
Affected Systems
The flaw impacts patriksimek:vm2 versions 3.10.2 through 3.11.6 when deployed on Node.js 26, which incorporates V8 14.6. Any installation that runs untrusted JavaScript inside vm2 is susceptible to the escape.
Risk and Exploitability
This vulnerability has a CVSS score of 9.3, indicating a critical severity. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog. The exploit requires that the attacker be able to execute JavaScript that is evaluated inside the vm2 sandbox and that the sandboxed code invokes Promise.finally to trigger the bypass. Only environments that expose the sandboxed runtime to untrusted input are at risk, and the attack vector is the injection of specially crafted Promise usage into the sandbox.
OpenCVE Enrichment
Github GHSA