criticalCVSS 10Vulnerability

CVE-2026-92956

## Summary There is a sandbox escape in vm2 `3.11.5` / current HEAD when it is used on Node.js 26. The issue is reachable from a default `new VM()` sandbox. No `NodeVM`, `require` permission, host object injection, or intentionally unsafe configuration is required. The escape is a patch-bypass of the same security invariant addressed by GHSA-6j2x-vhqr-qr7q. The earlier fix removed the JSPI entry points `WebAssembly.promising` and `WebAssembly.Suspending`, because those APIs exposed a Promise path whose host-realm `Promise.prototype` was not intercepted by vm2's Promise hardening or bridge layer. The same unsafe class remains reachable through `WebAssembly.compileStreaming` and `WebAssembly.instantiateStreaming`. On Node 26, these streaming APIs can produce a raw host-realm Promise path that rejects with a host-realm error. By controlling `Symbol.species` through `Promise.prototype.finally`, sandbox code can receive that raw host error object, walk from the host error constructor to the host `Function` constructor, and recover the real host `process` object. The proof of concept demonstrates this by first showing that direct access to `process`, `require`, and constructor-based escapes are blocked in the same default VM. It then reaches the host `process`, verifies that the recovered pid matches the parent Node process, and writes a harmless marker file through host `fs`. ## Impact This is a sandbox escape. In applications that expose vm2 execution to attacker-controlled JavaScript, the issue can become host code execution in the context of the Node.js process running the sandbox. This is not remote code execution by default. The remote aspect depends on the embedding application. The accurate framing is: > An attacker who can supply JavaScript to a vm2 `VM` sandbox on Node 26 can break out of the vm2 boundary and obtain host Node.js capabilities. This matters for services that use vm2 as a security boundary for untrusted JavaScript, including plugin runne

Properties

severity
critical
summary
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
epss_score
0.00587
cvss_score
10
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:34:22Z
source_url
https://github.com/advisories/GHSA-wjwh-qqvp-g4p4
ghsa_updated
2026-10-05T22:34:24Z
ghsa_id
GHSA-wjwh-qqvp-g4p4
last_source
FIRST EPSS
cve_id
CVE-2026-92956
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.46196

Related Entities (6)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (2)

→[Weakness]Protection Mechanism Failure
→[Weakness]Improper Control of Dynamically-Managed Code Resources

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92956 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal