PT-2026-94325 · Npm · Vm2
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.10.0 through 3.11.7
Description
Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary. While Promises created inside the sandbox are wrapped with a rejection-swallowing handler in
lib/setup-sandbox.js, the bridge only installs host-side rejection sanitizers when sandbox code calls .then, .catch, or .finally. Consequently, code running in the sandbox can invoke a host function that returns a rejected Promise, such as events.once() exposed via the NodeVM events builtin or other embedder-provided Promise-returning APIs, and ignore the return value. This leaves the host Promise unhandled, triggering the default Node.js unhandled-rejection behavior which terminates the host process.Recommendations
Update vm2 to version 3.11.8.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2