← Back to search

CVE-2026-92944

9.8 CRITICALpublic exploit available

Published 2026-09-17 · Updated 2026-09-19

AI risk analysis

Summary
This vulnerability allows attackers to bypass sandbox protections in vm2 versions 3.10.2 through 3.11.6 by exploiting the Promise.prototype.finally() method, leading to arbitrary code execution.
Exploitability
Exploitation requires the attacker to control the constructor Symbol.species within an async function, making it moderately difficult but feasible under certain conditions.
Blast radius
If exploited, this could result in full system compromise, as it allows arbitrary code execution within the Node.js environment.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to vm2 version 3.11.7 or later.
rcevm2nodejspromisesandbox

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.species, allowing them to reach the host Function constructor and process object for arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-693

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.