GHSA-mgj2-jqjq-q8ggCritical· 8.6▾ MidnightDuplicate Advisory: vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-gjq8-xm47-88rc. This link is maintained to preserve external references.
vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs host-side rejection sanitizers when sandbox code calls .then/.catch/.finally. As a result, code running in the sandbox can invoke a host function that returns a rejected Promise (for example events.once() exposed via the NodeVM events builtin, or any embedder-provided Promise-returning API) and simply ignore the return value, leaving the host Promise unhandled so that Node.js's default unhandled-rejection behavior terminates the host process. This is an incomplete fix of GHSA-hw58-p9xv-2mjh. The issue is fixed in version 3.11.8.
vm2 >= 3.10.0, <= 3.11.7Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92954High· 8.6vm2 is a sandbox library for running untrusted JavaScript in Node.js
CVE-2026-44001High· 8.6vm2 is an open source vm/sandbox for Node.js
GHSA-7rr2-8fr3-fjqxHigh· 6.8Duplicate Advisory: vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process
CVE-2026-100722Medium· 6.8vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap
GHSA-4xmw-hh9q-4q7cCritical· 9.0Duplicate Advisory: vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
GHSA-2vh9-cv26-p97mMedium· 5.8Duplicate Advisory: vm2: util.getCallSites() bypasses GHSA-v27g host-frame redaction, leaks host call stack