PT-2026-45032 · Root+3 · @Rootio/Vm2+1

CVE-2026-47210

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.4
Description A sandbox escape allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly JavaScript Promise Integration), specifically WebAssembly.promising and WebAssembly.Suspending. A JSPI-backed Promise can reach the Promise.prototype.finally() function in a manner that bypasses Promise-species hardening. This exposes a host-originated rejection object to attacker-controlled species logic, breaking the sandbox boundary. In certain environments, the rejection object's constructor chain can be used to access the host process object, leading to full system compromise, including arbitrary command execution and unauthorized file access.
Recommendations Update to version 3.11.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47210
GHSA-6J2X-VHQR-QR7Q

Affected Products

@Rootio/Vm2
Vm2