PT-2026-99449 · Npm · Vm2
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.12.2
Description
The software fails to apply host-side Promise rejection handling within the sandbox-to-host construct trap. In the
BaseHandler component, the apply trap utilizes the markHostPromiseHandled() function to sanitize returned values, but the construct path returns the result of Reflect.construct() without this sanitization. If a constructable host function is exposed and its constructor returns a native rejected Promise, an untrusted script can invoke it using the new operator. This allows a rejected host Promise to remain unhandled, which Node.js treats as an uncaught exception, leading to the termination of the host process.Recommendations
Update vm2 to version 3.12.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2