DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92937: CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

Vulnerability ID: CVE-2026-92937
CVSS Score: 10.0
Published: 2026-10-01

CVE-2026-92937 is a critical sandbox escape vulnerability in the vm2 Node.js library. Due to a logical failure in checking direct invocation targets inside the Proxy bridge, an attacker can register Promise callbacks using Function.prototype.call or Function.prototype.apply indirection. This bypasses the error sanitization wrappers, delivering raw host error objects directly to sandboxed callbacks and allowing the attacker to escape the sandbox and execute arbitrary shell commands on the host.

TL;DR

A critical bypass in the vm2 sandbox proxy lets untrusted code use Function call/apply indirection to bypass Promise rejection sanitizers, leading to remote code execution.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-94, CWE-693
  • Attack Vector: Network
  • CVSS v3.1 Score: 10.0 (Critical)
  • EPSS Score: 0.01033 (1.03%)
  • Exploit Status: Proof of Concept (PoC) available
  • Patch Version: 3.11.7

Affected Systems

  • Node.js applications running vm2 <= 3.11.6
  • vm2: <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: 3157869

Fix sandbox escape via Promise call/apply indirection

Mitigation Strategies

  • Update vm2 to version 3.11.7 or later
  • Migrate away from vm2 to secure sandboxes like WebAssembly or isolated hypervisors

Remediation Steps:

  1. Identify all occurrences of vm2 in dependencies
  2. Update package.json to require vm2 version 3.11.7
  3. Perform dependency audits to ensure older versions are not bundled

References


Read the full report for CVE-2026-92937 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)