External risk intelligence

vm2 Sandbox Escape Via Promise Indirection Allows Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-92937

The vulnerability exists in a JavaScript sandbox library (vm2) designed for use within Node.js applications. While it processes untrusted input, the library itself is a dependency embedded within backend applications rather than a standalone network-facing service or appliance, making direct public internet exposure uncommon and dependent on specific implementation choices by developers.

Code Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the vm2 library, a tool used to create sandboxed JavaScript environments within Node.js applications. This issue allows unprivileged code to escape the sandbox and execute arbitrary commands on the host system, posing a significant security risk if not properly addressed. The main concern at this time is confirming whether this specific library is in use and exposed within your environment.

  • Unsafe code in a JavaScript sandbox.
  • Allows remote control of host systems.
  • Confirm use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could escape the vm2 sandbox and execute code on the host Node.js process if an application improperly exposes a host-realm Promise to the sandbox. This could happen through an asynchronous function bridged into the sandbox or an async method of an external Node.js module. If this Promise rejects with an error containing a specific type of host object, the attacker could gain control over that host object and use it to run arbitrary commands.

  • Requires host Promise exposed to sandbox.
  • Triggered via indirection in Promise rejection handler.
  • Results in host process code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow untrusted code running within a sandboxed environment to escape and execute arbitrary commands on the host Node.js process. This is possible when the sandbox is configured to expose host-realm Promises, which can then be manipulated through indirect function calls to bypass security checks.

  • Host process commands and data.
  • Escaped sandbox execution via Promise indirection.
  • Arbitrary code execution on the host.

Operational Fix

Recommended remediation, mitigation, and detection steps

Platform and application teams are likely responsible for addressing this vulnerability within Node.js environments. The initial practical step is to inventory all instances of the affected technology, determine their reachability and criticality, and then identify the accountable owner for remediation planning.

  • Platform/Application teams should own this.
  • Verify sandbox usage and external inputs.
  • Plan updates during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and how is it used?

vm2 is a Node.js library designed to create isolated execution environments, known as sandboxes. Developers use it to run untrusted or user-provided JavaScript code safely by attempting to restrict that code's access to the main host application and the underlying operating system.

What is the vulnerability in CVE-2026-92937?

This vulnerability is a sandbox escape, classified as CWE-94 (Improper Control of Generation of Code). It occurs when the sandbox's security checks are bypassed, allowing code running inside the isolated environment to break out and execute arbitrary commands directly on the host system with the same privileges as the Node.js process.

How can an attacker trigger this sandbox escape?

An attacker needs the application to expose a host-realm Promise to the sandbox, often through asynchronous functions. The bug is triggered when a rejected Promise is handled using specific indirect methods like .call or .apply, which causes the sandbox to miss necessary security sanitization. Standard methods like direct .then(undefined, cb) calls are not affected.

Is my application at risk from this vulnerability?

According to Halo Surface Signal, this vulnerability is considered unlikely to be directly accessible from the internet because vm2 is an embedded dependency rather than a standalone network service. Risk depends entirely on whether your specific application logic bridges host-realm Promises into the sandbox, creating a potential path for exploitation.

How do I address this security issue?

The primary step is to conduct an inventory to identify where vm2 is utilized within your Node.js environments. Once identified, work with the application owners to assess if host-realm Promises are exposed to the sandbox. The recommended remediation is to update the vm2 library to version 3.11.7 or later, which contains the corrected security checks.

References