Description
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`.then` neutralization is installed only on the sandbox intrinsic `Promise.prototype`, so it never applies to a host Promise. Code running inside the sandbox can overwrite `p.constructor[Symbol.species]` on the host Promise and then call `p.then()` with no `onRejected` handler; V8 substitutes its internal Thrower, which re-throws the raw host rejection value into a resolve/reject closure captured by the attacker. This delivers an unsanitized, fully functional bridge proxy of the host object to sandboxed code, bypassing handleException and hostPromiseSanitizeReject. If the rejection value is host-pivotable (for example a host `process` object), this results in arbitrary code execution on the host. Fixed in 3.12.1.
Published: 2026-09-18
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in vm2, a Node.js sandboxing framework. When an embedder exposes a host API that returns a host-realm Promise, the bridge’s rejection sanitizer only protects sandbox-side Promises; host Promises are not neutralized. A sandboxed script can overwrite the host Promise’s constructor[Symbol.species] and then call then() without an onRejected handler. V8’s internal Thrower then re‑throws the raw rejection value into a resolve/reject closure captured by the attacker. If that rejection value is a host‑pivotable object, such as the process object, the attacker obtains a full‑functional bridge proxy of the host object and can execute arbitrary code on the host process. This results in a sandbox escape and full code execution on the host.

Affected Systems

The flaw affects the npm package patriksimek:vm2, versions 3.12.0 and earlier. Any Node.js application that uses these versions and passes host Promise objects into the vm2 sandbox is vulnerable. Updating to version 3.12.1 or later removes the escape path.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, although the potential impact remains high. The vulnerability is not listed in CISA KEV. The attack requires that an untrusted sandbox be able to see host Promise objects; if such APIs are present, an attacker can inject malicious code to trigger the escape.

Generated by OpenCVE AI on September 26, 2026 at 05:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.12.1 or newer
  • Restrict or remove host APIs that return Promise objects to the sandbox
  • Audit the sandbox configuration to limit exposed host APIs and reduce the chance of untrusted code accessing sensitive objects

Generated by OpenCVE AI on September 26, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-653
References
Metrics threat_severity

None

threat_severity

Critical


Sat, 19 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`.then` neutralization is installed only on the sandbox intrinsic `Promise.prototype`, so it never applies to a host Promise. Code running inside the sandbox can overwrite `p.constructor[Symbol.species]` on the host Promise and then call `p.then()` with no `onRejected` handler; V8 substitutes its internal Thrower, which re-throws the raw host rejection value into a resolve/reject closure captured by the attacker. This delivers an unsanitized, fully functional bridge proxy of the host object to sandboxed code, bypassing handleException and hostPromiseSanitizeReject. If the rejection value is host-pivotable (for example a host `process` object), this results in arbitrary code execution on the host. Fixed in 3.12.1.
Title vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species
First Time appeared Vm2 Project
Vm2 Project vm2
Weaknesses CWE-693
CPEs cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Vendors & Products Vm2 Project
Vm2 Project vm2
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:48:56.766Z

Reserved: 2026-09-18T11:01:45.930Z

Link: CVE-2026-93606

cve-icon Vulnrichment

Updated: 2026-09-18T17:48:51.494Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:12.500

Modified: 2026-09-18T18:18:31.267

Link: CVE-2026-93606

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-18T13:20:15Z

Links: CVE-2026-93606 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T05:45:05Z

Weaknesses
  • CWE-653

    Improper Isolation or Compartmentalization

  • CWE-693

    Protection Mechanism Failure