criticalCVSS 9Vulnerability

CVE-2026-92934

## Summary vm2 `3.11.6` (this fork's latest release) contains an incomplete-fix bypass of the Error.cause host-reference sanitization added in GHSA-m283-3h24-438v (commit `7e3faaf`). Sandbox code that catches a host-wrapped `AggregateError` which is *revisited within a single `handleException` traversal* (self-cycle, mutual-cycle, or the same host aggregate referenced twice in `errors[]`) receives a live, unsanitized host proxy inside the "sanitized" `errors[]`, yielding full host RCE on the throw channel that the fix and Defense Invariant #3 explicitly promise to sanitize. ## Root Cause `handleException` (`lib/setup-sandbox.js`) breaks recursion cycles at line 1819 with `if (apply(localWeakMapGet, visited, [e])) return e;` — returning the RAW host carrier on revisit. For plain-`Error` carriers this is safe because `sanitizeErrorCause`/`sanitizeHostOwnProps` seal the host object **in place** on first visit. But `sanitizeAggregateError` (~1954-1972) snapshot-and-rebuilds host-wrapped carriers into a fresh `LocalAggregateError` and does NOT seal the original in place. When such a carrier is revisited within one traversal, line 1819 hands back the still-live raw host proxy, which the rebuild re-embeds via `sanitizedArr[sanitizedArr.length] = handleException(item, visited)` (line 1965) into the "sanitized" `errors[]`. ## Impact Full host RCE (`child_process.execSync`) and host info disclosure (`process.env`, `.pid`) from within the vm2 sandbox — a complete sandbox escape on the caught-exception (throw) channel. ## Proof of Concept ```js const {VM} = require('vm2'); const vm = new VM({ sandbox: { hostThrow(){ const shared = new AggregateError([], 'shared'); shared.leak = process; // incidental host ref throw new AggregateError([shared, shared], 'all failed'); // same host obj twice }}}); console.log(vm.run(` try { hostThrow(); } catch (e) { e.errors[1].leak.mainModule.require('child_process').execSync('id').toString(); }`

Properties

severity
critical
summary
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
epss_score
0.00762
cvss_score
9
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:38:04Z
source_url
https://github.com/advisories/GHSA-x965-fc75-jpqh
ghsa_updated
2026-10-05T22:38:05Z
ghsa_id
GHSA-x965-fc75-jpqh
last_source
FIRST EPSS
cve_id
CVE-2026-92934
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.53777

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Protection Mechanism Failure

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92934 (CVSS 9) — Ninja Signal Threat Intelligence | Ninja Signal