Description
vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host `process` object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows code running inside a default vm2 VM to escape the sandbox and gain host access. By exploiting the interaction between WebAssembly.compileStreaming or instantiateStreaming, a sandboxed promise can return a native host error that, when its species is manipulated through Promise.prototype.finally, allows traversal through the host Function constructor to the process object. This results in the ability to require native modules such as fs, execute arbitrary commands, and compromise the entire Node.js application and underlying operating system.

Affected Systems

All vm2 releases from 3.10.1 to 3.11.6 run on Node.js 26 are affected when a new VM is created with default settings. The vendor is patriksimek:vm2 and the exploitation does not require special configuration, permissions, or host object injection.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. No EPSS score is published, but the flaw does not demand privileged context or additional configuration, making exploitation potentially straightforward for an attacker who can supply sandbox code. The vulnerability is not listed in the CISA KEV catalog, yet its reliance on a core Node.js feature makes it a high-priority risk for any production environment that uses vm2.

Generated by OpenCVE AI on September 17, 2026 at 23:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later, which removes the exploitable code paths.
  • If an immediate upgrade is not possible, suspend or remove use of WebAssembly.compileStreaming and WebAssembly.instantiateStreaming in the application to block the attack vector.
  • Monitor runtime logs for unexpected WebAssembly compilation failures or exception patterns indicating an attempt to traverse the host error chain, and consider running the application under least‑privilege user accounts to limit potential damage.

Generated by OpenCVE AI on September 17, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wjwh-qqvp-g4p4 vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
History

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host `process` object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.
Title vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:20:26.124Z

Reserved: 2026-09-17T12:43:31.527Z

Link: CVE-2026-92956

cve-icon Vulnrichment

Updated: 2026-09-17T19:18:15.461Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:01.640

Modified: 2026-09-17T20:18:59.730

Link: CVE-2026-92956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure