Junglewise Threat Intelligence

CVE-2026-92944: vm2 sandbox escape via Promise.prototype.finally() on Node.js 26

CVE-2026-92944 · Severity: critical · CVSS 9.8 · Published 2026-09-17

Technologies: Vm2.

Executive brief

vm2 is a sandboxing library used to safely execute untrusted JavaScript code in isolated environments. This vulnerability allows attackers to break out of the sandbox and execute arbitrary code on the host system by exploiting a flaw in how Promise chains are validated, potentially compromising any application relying on vm2 to isolate user-supplied code.

Technical details

The vulnerability is a sandbox escape affecting vm2 versions 3.10.2 through 3.11.6 on Node.js 26. It exploits a stale PromiseThenLookupChain protector in V8 14.6 where Promise.prototype.finally() bypasses vm2's wrapper protections. An attacker can craft an async function that returns a Promise with an attacker-controlled constructor Symbol.species property, allowing them to reach the host Function constructor and process object, thereby executing arbitrary code outside the sandbox. The attack requires only the ability to execute code within the vm2 sandbox context. Patches should be available in later versions of vm2.

Affected products

  • vm2 vm2 3.10.2 through 3.11.6

Timeline

  • 2026-09-17: disclosed

References