GHSA-9538-79j2-h62hHigh· 7.1▾ TwilightDuplicate Advisory: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-f8gf-w286-fmq2. This link is maintained to preserve external references.
vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve, Promise.all, Promise.race, Promise.any, and Promise.allSettled) still assimilate attacker-supplied thenables: native promise resolution performs PromiseResolveThenableJob and invokes the sandboxed code's then method in a microtask without passing through the patched then, so the async restriction is never applied. As a result, sandboxed script can schedule work that runs after VM.run() or NodeVM.run() has returned and outside the configured timeout, continuing to execute after the host believes execution is complete.
vm2 <= 3.11.7Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92959High· 7.1vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM
GHSA-4xmw-hh9q-4q7cCritical· 9.0Duplicate Advisory: vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
GHSA-538q-xxpg-6h4rCritical· 10.0Duplicate Advisory: vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
GHSA-hwr5-cm8v-c76qCritical· 9.8Duplicate Advisory: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
GHSA-m7cq-7f2q-f9fhCritical· 9.9Duplicate Advisory: vm2 3.11.6 allows a sandboxed plugin to execute native code through `node:sqlite`
GHSA-wqg3-r97q-73xmCritical· 9.9Duplicate Advisory: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape