CVE-2026-92944
## Reporter - Name or handle: `[YMsora]` - Report date: 2026-08-14 ## Summary The latest published vm2 release, **3.11.5**, and the current `main` branch are vulnerable to a sandbox escape when used on Node.js 26. An ordinary fulfilled Promise created by an async function can retain an attacker-controlled `constructor[Symbol.species]` across `Promise.prototype.finally()`. vm2 installs wrappers on the intrinsic `Promise.prototype.then` and `catch` methods. On Node.js 26 / V8 14.6, V8's `SetPrototypeProperties` path updates these existing data properties without invalidating the `PromiseThenLookupChain` protector. `Promise.prototype.finally()` subsequently trusts the stale protector and uses an internal `InvokeThen` fast path that calls the original native `then`, bypassing vm2's wrapper and its `resetPromiseSpecies(this)` hardening. The attacker-controlled species constructor therefore supplies the resolve and reject functions used by a native Promise reaction. A calibrated stack overflow at that native reaction boundary yields a raw host-realm `RangeError` to the attacker-controlled reject function. Its constructor chain reaches the host `Function` constructor and consequently the host `process` object. The attached proof is non-destructive: it reads only `process.version`. It does not execute commands, access files, or perform network requests. ## Latest-version status Verified on 2026-08-14: - npm `latest`: `[email protected]` - `[email protected]` publication time: 2026-05-18T15:37:26.138Z - npm `gitHead`: `7a1f5100b96f48d34e0fe104ab37c0acc5944f92` - npm tarball: `https://registry.npmjs.org/vm2/-/vm2-3.11.5.tgz` - npm integrity: `sha512-RSrkBiwrj6FRU+QdqNs6KG0XdlvJCjpQ4GXiqmMbrhmwfu5k/XIMpAer0L8f6iuf0uJ3a4T1xJN126Q8yf0VIA==` - GitHub default branch `main` HEAD: the same commit, also tagged `v3.11.5` - latest formal Node.js release: `v26.7.0`, V8 `14.6.202.34` The npm tarball and current GitHub `main` contain the same relevant `lib/setup-sandbox.js` Git blob. There is
Properties
- severity
- critical
- summary
- vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
- cvss_score
- 9.8
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T15:28:07Z
- source_url
- https://github.com/advisories/GHSA-27g9-p43v-cw3v
- ghsa_updated
- 2026-10-01T15:28:08Z
- ghsa_id
- GHSA-27g9-p43v-cw3v
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-92944
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- false
Related Entities (5)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
Explore deeper with Ninja Signal's threat intelligence graph