PT-2026-94306 · Npm · Vm2

·

CVE-2026-92934

·

Published

2026-08-25

·

Updated

2026-09-17

CVSS v4.0

9.5

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.8
Description An incomplete fix for Error.cause sanitization allows a sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit a cycle detection bypass in the handleException() function to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.
Recommendations Update vm2 to version 3.11.8 or later.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14938
CVE-2026-92934
GHSA-X965-FC75-JPQH

Affected Products

Vm2