Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mausamrijall

#32729of 57,313
8.7Total CVSS
Vulnerabilities · 1
PT-2026-94314
8.7
2026-09-17
Npm · Vm2 · CVE-2026-92942
**Name of the Vulnerable Software and Affected Versions** vm2 versions prior to 3.11.7 **Description** The software fails to enforce the `timeout` option for code executed outside the synchronous `run()` function. This occurs because the timeout only wraps the ` runScript()` call via `doWithTimeout()` in the `lib/vm.js` file. Additionally, `FinalizationRegistry` and `WeakRef` are exposed to sandboxed code without modifications. An attacker can register a `FinalizationRegistry` cleanup callback and remove all strong references to the object. While the `run()` function may return within the timeout, the V8 garbage collector later invokes the cleanup callback outside the timeout accounting. A busy loop within this callback can block the host event loop indefinitely, leading to a denial of service. The timing of this execution depends on the garbage collector's behavior, such as memory pressure or the use of the `--expose-gc` flag. **Recommendations** Update to version 3.11.7 or later.