CVE-2026-92956: Protection Mechanism Failure in patriksimek vm2
vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host `process` object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.
AI Analysis
Technical Summary
The vm2 library versions 3.10.1 through 3.11.6 contain a sandbox escape vulnerability exploitable on Node.js 26. The issue arises because WebAssembly.compileStreaming and WebAssembly.instantiateStreaming produce raw host-realm Promises that reject with host-realm error objects. By controlling Symbol.species via Promise.prototype.finally, sandboxed code can obtain the raw host error, traverse from the error constructor to the host Function constructor, and ultimately recover the real host process object. This grants the sandboxed code full access to host Node.js capabilities, such as the filesystem module, without requiring NodeVM, require permissions, or any unsafe configuration. This vulnerability bypasses a previous fix (GHSA-6j2x-vhqr-qr7q) that removed certain JSPI entry points. The issue is resolved in vm2 version 3.11.7.
Potential Impact
Exploitation of this vulnerability allows an attacker running code inside a vm2 sandbox to escape the sandbox and gain full access to the host Node.js process. This includes access to sensitive host modules like 'fs', enabling arbitrary code execution and potentially full system compromise. The vulnerability requires no user interaction or elevated privileges and is remotely exploitable in environments running affected vm2 versions on Node.js 26.
Mitigation Recommendations
Upgrade vm2 to version 3.11.7 or later, where this vulnerability is fixed. No other mitigations are indicated or effective since the vulnerability does not require unsafe configurations or permissions. Patch status is confirmed by the vendor advisory stating the fix is in 3.11.7.
CVE-2026-92956: Protection Mechanism Failure in patriksimek vm2
Description
vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host `process` object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.
CVSS v4.0
Score 10.0critical
Affected software
patriksimek
vm2
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vm2 library versions 3.10.1 through 3.11.6 contain a sandbox escape vulnerability exploitable on Node.js 26. The issue arises because WebAssembly.compileStreaming and WebAssembly.instantiateStreaming produce raw host-realm Promises that reject with host-realm error objects. By controlling Symbol.species via Promise.prototype.finally, sandboxed code can obtain the raw host error, traverse from the error constructor to the host Function constructor, and ultimately recover the real host process object. This grants the sandboxed code full access to host Node.js capabilities, such as the filesystem module, without requiring NodeVM, require permissions, or any unsafe configuration. This vulnerability bypasses a previous fix (GHSA-6j2x-vhqr-qr7q) that removed certain JSPI entry points. The issue is resolved in vm2 version 3.11.7.
Potential Impact
Exploitation of this vulnerability allows an attacker running code inside a vm2 sandbox to escape the sandbox and gain full access to the host Node.js process. This includes access to sensitive host modules like 'fs', enabling arbitrary code execution and potentially full system compromise. The vulnerability requires no user interaction or elevated privileges and is remotely exploitable in environments running affected vm2 versions on Node.js 26.
Mitigation Recommendations
Upgrade vm2 to version 3.11.7 or later, where this vulnerability is fixed. No other mitigations are indicated or effective since the vulnerability does not require unsafe configurations or permissions. Patch status is confirmed by the vendor advisory stating the fix is in 3.11.7.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T12:43:31.527Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aac405055bf5e2cf5cb2384
Added to database: 09/17/2026, 19:32:32 UTC
Last enriched: 09/17/2026, 19:46:36 UTC
Last updated: 09/18/2026, 00:39:20 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.