Description
vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs host-side rejection sanitizers when sandbox code calls .then/.catch/.finally. As a result, code running in the sandbox can invoke a host function that returns a rejected Promise (for example events.once() exposed via the NodeVM events builtin, or any embedder-provided Promise-returning API) and simply ignore the return value, leaving the host Promise unhandled so that Node.js's default unhandled-rejection behavior terminates the host process. This is an incomplete fix of GHSA-hw58-p9xv-2mjh. The issue is fixed in version 3.11.8.
Published: 2026-09-17
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

vm2 implements a sandbox for executing untrusted JavaScript. In versions 3.10.0 through 3.11.7, Promises returned from the host realm into the sandbox are not flagged as handled when they cross the bridge boundary. Only Promises created inside the sandbox receive a rejection‑swallowing wrapper, and the bridge installs host‑side rejection sanitizers only when sandbox code calls .then, .catch, or .finally. Consequently, sandbox code that calls a host function returning a rejected Promise and simply ignores the returned value leaves an unhandled rejection in the host process. Node.js’s default unhandled‑rejection policy terminates the process, resulting in a denial‑of‑service. The flaw can be triggered by any sandboxed code that invokes a host API such as events.once exposed via the NodeVM events builtin, or other embedder‑provided Promise‑returning APIs.

Affected Systems

The vulnerability affects the patriksimek:vm2 sandbox library for Node.js. All releases from version 3.10.0 up to and including 3.11.7 are impacted. The issue was fixed in version 3.11.8 and later.

Risk and Exploitability

The CVSS base score of 9.2 indicates high severity. Exploitation requires running untrusted JavaScript that calls a host function returning a rejected Promise without handling the rejection. While no publicly known exploits are listed in the CISA KEV catalog, the lack of mitigation in vulnerable releases means that any such sandboxed code can terminate the hosting Node.js process. The EPSS score is not available, so the probability of exploitation cannot be quantified, but the worst‑case impact is a critical application shutdown.

Generated by OpenCVE AI on September 17, 2026 at 23:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.8 or later.
  • If an upgrade is not possible, run sandboxed code in an isolated process or container that can be restarted independently.
  • Ensure that sandbox code handling of host‑returned Promises includes .catch or .finally to consume rejections, preventing unhandled rejections on the host side.

Generated by OpenCVE AI on September 17, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gjq8-xm47-88rc vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
History

Sat, 26 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 26 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise vm2 3.10.0 through 3.11.7 Denial of Service via Host Promise

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs host-side rejection sanitizers when sandbox code calls .then/.catch/.finally. As a result, code running in the sandbox can invoke a host function that returns a rejected Promise (for example events.once() exposed via the NodeVM events builtin, or any embedder-provided Promise-returning API) and simply ignore the return value, leaving the host Promise unhandled so that Node.js's default unhandled-rejection behavior terminates the host process. This is an incomplete fix of GHSA-hw58-p9xv-2mjh. The issue is fixed in version 3.11.8.
Title vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-26T13:30:00.813Z

Reserved: 2026-09-17T12:43:31.527Z

Link: CVE-2026-92954

cve-icon Vulnrichment

Updated: 2026-09-21T17:15:51.171Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:01.320

Modified: 2026-09-21T18:17:15.997

Link: CVE-2026-92954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses