← Back to search

CVE-2026-92934

9 CRITICALpublic exploit available

Published 2026-09-17 · Updated 2026-09-17

AI risk analysis

Summary
This flaw allows attackers to bypass sandbox restrictions and execute arbitrary code, posing a critical risk to system security.
Exploitability
Exploitation is moderately difficult requiring specific conditions, such as the presence of host-wrapped AggregateError objects and a traversal through a single exception handler.
Blast radius
If exploited, this vulnerability could lead to full remote code execution and process information disclosure, impacting the entire system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to vm2 version 3.11.8 or later.
rcewebvm2

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-693

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.