Description
vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.species, allowing them to reach the host Function constructor and process object for arbitrary code execution.
Published: 2026-09-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The vulnerability in vm2 permits a sandbox escape that results in arbitrary code execution. When Promise.prototype.finally is invoked, the sandbox’s wrapper protections are bypassed due to a stale PromiseThenLookupChain protector in V8 14.6, which is bundled in Node.js 26. By crafting an async function that returns a Promise whose Symbol.species points to an attacker‑controlled constructor, an attacker can obtain the host Function constructor and the process object, enabling execution of malicious code.

Affected Systems

The flaw impacts patriksimek:vm2 versions 3.10.2 through 3.11.6 when deployed on Node.js 26, which incorporates V8 14.6. Any installation that runs untrusted JavaScript inside vm2 is susceptible to the escape.

Risk and Exploitability

This vulnerability has a CVSS score of 9.3, indicating a critical severity. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog. The exploit requires that the attacker be able to execute JavaScript that is evaluated inside the vm2 sandbox and that the sandboxed code invokes Promise.finally to trigger the bypass. Only environments that expose the sandboxed runtime to untrusted input are at risk, and the attack vector is the injection of specially crafted Promise usage into the sandbox.

Generated by OpenCVE AI on September 17, 2026 at 23:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the patriksimek/vm2 repository for the latest releases that address this issue and upgrade to that version if it is available.
  • If an upgrade cannot be performed immediately, rewrite any sandboxed code that uses Promise.prototype.finally to use then() or other safe cleanup patterns that do not trigger the PromiseThenLookupChain bypass.
  • Deploy vm2 in a tightly isolated environment—such as a dedicated process or container with minimal privilege—and restrict the Node.js runtime to a minimal set of capabilities to reduce the impact of a potential escape. If possible, upgrade Node.js to a version where V8 does not contain the vulnerable promise chain.

Generated by OpenCVE AI on September 17, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-27g9-p43v-cw3v vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.species, allowing them to reach the host Function constructor and process object for arbitrary code execution.
Title vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:31:01.016Z

Reserved: 2026-09-17T12:43:03.567Z

Link: CVE-2026-92944

cve-icon Vulnrichment

Updated: 2026-09-19T02:30:55.915Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:59.623

Modified: 2026-09-19T03:17:18.580

Link: CVE-2026-92944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:13Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure