---
id: GHSA-538q-xxpg-6h4r
title: >-
  Duplicate Advisory: vm2 sandbox escape via WebAssembly.compileStreaming
  Promise species bypass
summary: >-
  Duplicate Advisory: vm2 sandbox escape via WebAssembly.compileStreaming
  Promise species bypass
severity: critical
cvss: 10
cwe:
  - CWE-693
vendor: vm2
product: vm2
ecosystem: npm
affected:
  - 'vm2 >= 3.10.1, <= 3.11.6'
published: '2026-09-17'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T22:34:15Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-538q-xxpg-6h4r'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-wjwh-qqvp-g4p4'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92956'
  - url: >-
      https://www.vulncheck.com/advisories/vm2-3.10.1-through-3.11.6-sandbox-escape-via-webassembly-compilestreaming
  - url: 'https://github.com/advisories/GHSA-538q-xxpg-6h4r'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-05T22:35:24.744Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-wjwh-qqvp-g4p4. This link is maintained to preserve external references.

## Original Description
vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host `process` object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.

## Affected packages

- `vm2 >= 3.10.1, <= 3.11.6`

## Remediation

Refer to the advisory for the patched release.
