DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92944: CVE-2026-92944: Sandbox Escape in vm2 via Stale V8 PromiseThenLookupChain Protector

CVE-2026-92944: Sandbox Escape in vm2 via Stale V8 PromiseThenLookupChain Protector

Vulnerability ID: CVE-2026-92944
CVSS Score: 9.8
Published: 2026-10-01

A critical engine-level reachability failure in Node.js 26 running V8 14.6 allows attackers to escape the vm2 sandbox environment. When consecutive prototype properties are modified using sequential assignments, a V8 optimization bug fails to invalidate the PromiseThenLookupChain protector. By calling Promise.prototype.finally, the attacker bypasses the vm2 wrappers, hijacks the promise reaction using a custom constructor, triggers a calibrated stack overflow to capture a host-realm RangeError, and executes arbitrary shell commands on the host.

TL;DR

An optimization bug in the V8 engine on Node.js 26 fails to invalidate a promise lookup protector when properties are assigned sequentially, allowing attackers to bypass vm2's promise wrappers and achieve full sandbox escape and remote code execution.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-693
  • Attack Vector: Network
  • CVSS Score: 9.8
  • EPSS Score: 0.00841
  • Impact: Arbitrary Code Execution / Sandbox Escape
  • Exploit Status: PoC
  • KEV Status: No

Affected Systems

  • vm2 running on Node.js 26 (V8 14.6)
  • vm2: >= 3.10.2, <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: c7df2e2

Install promise wrappers via defineProperty and explicitly wrap finally

Commit: 4635ddd

Additional sandbox promise setup adjustments

Commit: 7b26e81

Sandbox promise wrapper cleanup

Exploit Details

  • GitHub: Advisory containing the concept payload and details of the escape

Mitigation Strategies

  • Upgrade vm2 to 3.11.7 or higher to apply property definition overrides
  • Run Node.js with the --no-proto-assign-seq-opt flag to disable the buggy V8 optimization
  • Migrate to process-isolated sandbox solutions like isolated-vm

Remediation Steps:

  1. Identify all projects and dependencies relying on vm2
  2. Update the package.json dependency to 'vm2': '^3.11.7'
  3. In corporate CI/CD pipelines, configure Node.js launch configurations with the --no-proto-assign-seq-opt flag as a defense-in-depth measure

References


Read the full report for CVE-2026-92944 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)