External risk intelligence

vm2 Sandbox Unhandled Promise Rejection Denial of Service

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-92954

The vulnerable component is a developer library used to execute untrusted code. It is an internal dependency integrated into applications rather than a standalone network-facing product. Exposure depends entirely on whether a developer incorporates the library into an internet-facing application, making direct public internet exposure uncommon and atypical for this component.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The vm2 library, used for safely executing untrusted JavaScript in Node.js environments, has a vulnerability that could allow malicious code to terminate the host process. This issue arises from how promises are handled between the sandbox and the main program, potentially leading to unhandled rejections that crash the system.

  • Sandbox code can crash the host process.
  • A serious flaw in a common JavaScript sandbox.
  • Confirm if this library is used to mitigate risk.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted JavaScript code to a Node.js application that uses the vm2 library. This code will cause the application to process a rejected host promise in a way that leads to an unhandled rejection, ultimately crashing the host process.

  • Untrusted code execution in Node.js environment.
  • Triggering unhandled promise rejections.
  • Denial of service by crashing the host process.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact Node.js applications using the vm2 library to execute untrusted JavaScript. When an attacker can control code within the sandbox, they may be able to trigger unhandled promise rejections from host functions. This could lead to the Node.js process terminating unexpectedly, causing a denial of service for the application.

  • Node.js host process.
  • Ignored host Promise return values.
  • Application crash and denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 library is a development dependency, meaning its ownership and exposure depend on how it's integrated into applications. Application owners or platform teams are likely responsible for managing its use, with security teams involved if it poses a direct risk to production environments. The first step is to identify applications using vm2, assess their criticality and reachability, and then plan remediation.

  • Application owners should manage remediation.
  • Verify where vm2 is deployed.
  • Plan fixes based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and how is it used?

vm2 is a JavaScript library for Node.js designed to create isolated environments, or sandboxes, where untrusted code can run safely. Developers use it when they need to execute user-provided scripts without allowing that code to access the main application's memory, file system, or critical system processes.

How does CVE-2026-92954 represent a vulnerability?

This vulnerability is classified as CWE-248, an uncaught exception issue. It occurs because the sandbox fails to properly manage Promise objects returned by the host environment. If sandboxed code triggers a rejected Promise from the host and ignores it, the default Node.js behavior treats this as an unhandled rejection, which forces the entire host process to terminate.

When does this vulnerability trigger?

An attacker triggers this by executing code within the sandbox that interacts with specific host-provided functions, such as Node.js built-ins or custom APIs, that return a Promise. The crash does not occur if the sandboxed code handles the Promise normally or if the application does not use host-provided APIs that return Promises within the sandbox boundary.

Is my application at risk from this CVE?

Risk depends on your specific implementation. According to Halo Surface Signal, vm2 is a developer library, not a standalone service. You are only potentially affected if your application uses an older version of vm2 (3.10.0 through 3.11.7) to process untrusted input that an attacker can control.

What is the first step to address this issue?

The priority is to locate all instances of the vm2 library within your codebase to see if they fall within the affected version range. Once identified, the standard resolution is to update to version 3.11.8 or higher, which contains the necessary security fixes to properly handle these host-side Promises.

References