PT-2026-94330 · Npm · Vm2

·

CVE-2026-92959

·

Published

2026-08-27

·

Updated

2026-09-17

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.8
Description The software fails to fully enforce the allowAsync: false option within VM and NodeVM. Although localPromise.prototype.then is replaced to prevent asynchronous operations, the sandbox's Promise static methods—specifically Promise.resolve, Promise.all, Promise.race, Promise.any, and Promise.allSettled—still accept attacker-supplied thenables. This occurs because native promise resolution executes a PromiseResolveThenableJob and invokes the then method of the sandboxed code in a microtask, bypassing the patched handler. Consequently, a sandboxed script can schedule tasks that execute after VM.run() or NodeVM.run() has returned and beyond the configured timeout, allowing execution to continue after the host assumes it has finished.
Recommendations Update to version 3.11.8 or later.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15025
CVE-2026-92959
GHSA-F8GF-W286-FMQ2

Affected Products

Vm2