GHSA-7rr2-8fr3-fjqxHigh· 6.8▾ TwilightDuplicate Advisory: vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-2v2p-6j97-cjg9. This link is maintained to preserve external references.
vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.construct without the same sanitization. If an embedder exposes a constructable host function whose constructor returns a native rejected Promise, an untrusted script executed via VM.run can invoke it with new and ignore the result; the rejected host Promise crosses the bridge unhandled and, under Node's strict unhandled-rejection policy, is promoted to an uncaught exception that terminates the host process.
vm2 < 3.12.2Upgrade to a patched release:
vm2 3.12.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100722Medium· 6.8vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap
CVE-2026-44001High· 8.6vm2 is an open source vm/sandbox for Node.js
GHSA-mgj2-jqjq-q8ggCritical· 8.6Duplicate Advisory: vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
CVE-2026-92954High· 8.6vm2 is a sandbox library for running untrusted JavaScript in Node.js
GHSA-4xmw-hh9q-4q7cCritical· 9.0Duplicate Advisory: vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
GHSA-2vh9-cv26-p97mMedium· 5.8Duplicate Advisory: vm2: util.getCallSites() bypasses GHSA-v27g host-frame redaction, leaks host call stack