Npm · Vm2 · CVE-2026-92942
**Name of the Vulnerable Software and Affected Versions**
vm2 versions prior to 3.11.7
**Description**
The software fails to enforce the `timeout` option for code executed outside the synchronous `run()` function. This occurs because the timeout only wraps the ` runScript()` call via `doWithTimeout()` in the `lib/vm.js` file. Additionally, `FinalizationRegistry` and `WeakRef` are exposed to sandboxed code without modifications. An attacker can register a `FinalizationRegistry` cleanup callback and remove all strong references to the object. While the `run()` function may return within the timeout, the V8 garbage collector later invokes the cleanup callback outside the timeout accounting. A busy loop within this callback can block the host event loop indefinitely, leading to a denial of service. The timing of this execution depends on the garbage collector's behavior, such as memory pressure or the use of the `--expose-gc` flag.
**Recommendations**
Update to version 3.11.7 or later.