PT-2026-45032 · Root+3 · @Rootio/Vm2+1
CVE-2026-47210
·
Published
2026-05-29
·
Updated
2026-07-21
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.4
Description
A sandbox escape allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly JavaScript Promise Integration), specifically
WebAssembly.promising and WebAssembly.Suspending. A JSPI-backed Promise can reach the Promise.prototype.finally() function in a manner that bypasses Promise-species hardening. This exposes a host-originated rejection object to attacker-controlled species logic, breaking the sandbox boundary. In certain environments, the rejection object's constructor chain can be used to access the host process object, leading to full system compromise, including arbitrary command execution and unauthorized file access.Recommendations
Update to version 3.11.4.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Rootio/Vm2
Vm2