CVE-2026-93606 PUBLISHED

vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species

Assigner: VulnCheck
Reserved: 18.09.2026 Published: 18.09.2026 Updated: 18.09.2026

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in VM and NodeVM. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps then/catch rejection slots that hold a function, and the sandbox-side Symbol.species/.then neutralization is installed only on the sandbox intrinsic Promise.prototype, so it never applies to a host Promise. Code running inside the sandbox can overwrite p.constructor[Symbol.species] on the host Promise and then call p.then() with no onRejected handler; V8 substitutes its internal Thrower, which re-throws the raw host rejection value into a resolve/reject closure captured by the attacker. This delivers an unsanitized, fully functional bridge proxy of the host object to sandboxed code, bypassing handleException and hostPromiseSanitizeReject. If the rejection value is host-pivotable (for example a host process object), this results in arbitrary code execution on the host. Fixed in 3.12.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor patriksimek
Product vm2
Versions Default: unaffected
  • affected from 0 to 3.12.1 (excl.)
  • Version 3.12.1 is unaffected

References

Problem Types

  • Protection Mechanism Failure CWE