criticalCVSS 8.6Vulnerability

CVE-2026-92954

## Summary vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) can still be used to terminate the host Node.js process when sandbox code calls a host-realm function that returns a rejected host Promise and then ignores the returned value. This is an incomplete-fix variant of the `GHSA-hw58-p9xv-2mjh` unhandled rejection hardening. The `localPromise` constructor now catches and consumes sandbox-created unhandled rejections, but host Promises returned across the bridge are not marked handled at the bridge boundary. If the sandbox does not attach `.catch()` or `.then(..., onRejected)`, Node's default unhandled rejection behavior terminates the host process. ## Technical Details `lib/setup-sandbox.js` hardens sandbox-created Promises by wrapping the executor and attaching a benign swallow tail: ```js apply(globalPromisePrototypeThen, this, [undefined, localPromiseSwallow]); ``` That only applies to `localPromise` instances created inside the sandbox. Host-returned Promises cross the membrane through the bridge apply path. The bridge wraps callbacks when sandbox code later calls `.then`, `.catch`, or `.finally` on a host Promise: ```js bridge.setHostPromiseSanitizers(e => handleException(from(e)), from); ``` However, if sandbox code ignores the returned host Promise, no host-side rejection handler is attached. The original host Promise remains unhandled and Node terminates the host process under the default unhandled-rejection behavior. `NodeVM` provides an in-repository example of this primitive through the special `events` builtin wrapper. `lib/builtin.js` passes host `EventEmitter.once` into the sandbox: ```js once: EventEmitter.once, ``` Then `lib/events.js` re-exports it: ```js if (host.once) module.exports.once = host.once; ``` Calling `events.once(ee, 'message')` and then emitting `error` on `ee` returns a rejected host Promise through that wrapper. If ignored by sandbox code, it terminates the host process. ## Impact An

Properties

severity
critical
summary
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
epss_score
0.00488
cvss_score
8.6
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:45:48Z
source_url
https://github.com/advisories/GHSA-gjq8-xm47-88rc
ghsa_updated
2026-10-05T22:45:49Z
ghsa_id
GHSA-gjq8-xm47-88rc
last_source
FIRST EPSS
cve_id
CVE-2026-92954
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.39838

Related Entities (6)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (2)

→[Weakness]Improper Check or Handling of Exceptional Conditions
→[Weakness]Uncaught Exception

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92954 (CVSS 8.6) — Ninja Signal Threat Intelligence | Ninja Signal