CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2
Vulnerability ID: CVE-2026-92937
CVSS Score: 10.0
Published: 2026-10-01
CVE-2026-92937 is a critical sandbox escape vulnerability in the vm2 Node.js library. Due to a logical failure in checking direct invocation targets inside the Proxy bridge, an attacker can register Promise callbacks using Function.prototype.call or Function.prototype.apply indirection. This bypasses the error sanitization wrappers, delivering raw host error objects directly to sandboxed callbacks and allowing the attacker to escape the sandbox and execute arbitrary shell commands on the host.
TL;DR
A critical bypass in the vm2 sandbox proxy lets untrusted code use Function call/apply indirection to bypass Promise rejection sanitizers, leading to remote code execution.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-94, CWE-693
- Attack Vector: Network
- CVSS v3.1 Score: 10.0 (Critical)
- EPSS Score: 0.01033 (1.03%)
- Exploit Status: Proof of Concept (PoC) available
- Patch Version: 3.11.7
Affected Systems
- Node.js applications running vm2 <= 3.11.6
-
vm2: <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: 3157869
Fix sandbox escape via Promise call/apply indirection
Mitigation Strategies
- Update vm2 to version 3.11.7 or later
- Migrate away from vm2 to secure sandboxes like WebAssembly or isolated hypervisors
Remediation Steps:
- Identify all occurrences of vm2 in dependencies
- Update package.json to require vm2 version 3.11.7
- Perform dependency audits to ensure older versions are not bundled
References
- Official GitHub Advisory
- NVD Official CVE Page
- CVE.org Record
- Fix Commit
- Official Version Release (v3.11.7)
Read the full report for CVE-2026-92937 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)