{"id":"CVE-2026-92934","published":"2026-09-17T14:17:57.513","lastModified":"2026-09-17T15:17:00.520","description":"vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.","cvssScore":9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-693"],"vendors":[],"products":[],"references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-x965-fc75-jpqh","tags":[]},{"url":"https://www.vulncheck.com/advisories/vm2-before-3.11.8-sandbox-escape-rce-via-aggregateerror","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-x965-fc75-jpqh","tags":[]}],"exploitRefs":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-x965-fc75-jpqh","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-x965-fc75-jpqh","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows attackers to bypass sandbox restrictions and execute arbitrary code, posing a critical risk to system security.","exploitability":"Exploitation is moderately difficult requiring specific conditions, such as the presence of host-wrapped AggregateError objects and a traversal through a single exception handler.","blast_radius":"If exploited, this vulnerability could lead to full remote code execution and process information disclosure, impacting the entire system.","remediation":"Upgrade to vm2 version 3.11.8 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","vm2"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:13:19.487Z"}}