PT-2026-95385 · Npm · Vm2

CVE-2026-93606

·

Published

2026-09-03

·

Updated

2026-09-20

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.12.1
Description A sandbox escape exists in VM and NodeVM when an embedder exposes a host API that returns a host-realm Promise. The bridge's rejection sanitizer, specifically the functions hostPromiseSanitizeReject(), makeSanitizedPromiseCallback(), and normalizeHostPromiseCallbacks() in lib/bridge.js, only wraps then/catch rejection slots that contain a function. Because the Symbol.species/.then neutralization is only applied to the sandbox intrinsic Promise.prototype, it does not affect host Promises.
An attacker running code inside the sandbox can overwrite p.constructor[Symbol.species] on a host Promise and call p.then() without an onRejected handler. This causes V8 to use its internal Thrower, which re-throws the raw host rejection value into a closure captured by the attacker. This process delivers an unsanitized bridge proxy of the host object to the sandboxed code, bypassing handleException() and hostPromiseSanitizeReject(). If the rejection value is host-pivotable, such as a host process object, it can lead to arbitrary code execution on the host. A public demonstration has shown host command execution and access to host-only environment data.
Recommendations Update to version 3.12.1. As a temporary mitigation, suspend the execution of untrusted scripts or remove the exposed host API that returns host-realm Promises. Restrict the authority of the worker process by reducing credentials, filesystem permissions, and network access.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14925
CVE-2026-93606
GHSA-6454-5X88-M6JW

Affected Products

Vm2