PT-2026-95382 · Npm · Vm2

·

CVE-2026-93603

·

Published

2026-09-03

·

Updated

2026-09-19

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.12.1
Description An issue exists in the apply trap of the bridge (lib/bridge.js) where a nullish this receiver is not correctly handled. When sandboxed code invokes a host-provided non-strict (sloppy-mode) function without a receiver, the undefined receiver is passed to the host call. V8 then substitutes the host realm's global object for this, which vm2 wraps and returns to the sandbox. This provides the sandboxed script with a live proxy of the host global, enabling a complete sandbox escape. An attacker can access the process object to execute arbitrary code or commands on the host, such as using process.getBuiltinModule('child process').execSync. This requires the embedding application to expose at least one non-strict host function to the sandbox; strict-mode and ES module host functions are not affected.
Recommendations Update to version 3.12.1. As a temporary mitigation, ensure that no non-strict host functions are exposed to the sandbox.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14926
CVE-2026-93603
GHSA-J89J-5M6R-CR2Q

Affected Products

Vm2