PT-2026-94325 · Npm · Vm2

·

CVE-2026-92954

·

Published

2026-09-17

·

Updated

2026-09-21

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions vm2 versions 3.10.0 through 3.11.7
Description Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary. While Promises created inside the sandbox are wrapped with a rejection-swallowing handler in lib/setup-sandbox.js, the bridge only installs host-side rejection sanitizers when sandbox code calls .then, .catch, or .finally. Consequently, code running in the sandbox can invoke a host function that returns a rejected Promise, such as events.once() exposed via the NodeVM events builtin or other embedder-provided Promise-returning APIs, and ignore the return value. This leaves the host Promise unhandled, triggering the default Node.js unhandled-rejection behavior which terminates the host process.
Recommendations Update vm2 to version 3.11.8.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92954
GHSA-GJQ8-XM47-88RC

Affected Products

Vm2