External risk intelligence

vm2 Sandbox Escape via Host Promise `Symbol.species` Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-93606

This vulnerability exists in a JavaScript library (vm2) used for sandboxing code within an application. It is a build-time dependency or an internal library component, not an internet-facing service, appliance, or application itself. Exposure depends entirely on how a developer integrates the library, making public-internet-facing reachability highly unlikely by design.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in the vm2 JavaScript library, which is used for isolating code. The issue allows attackers to escape the sandbox and potentially execute arbitrary code on the host system if specific conditions related to how Promises are handled are met.

  • A library for running untrusted code can be bypassed.
  • This could allow an attacker to run malicious code.
  • Confirm if this library is used in your environment.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by sending a specially crafted promise to a sandboxed environment that exposes host APIs. By manipulating the promise's constructor, an attacker could bypass security controls and execute arbitrary code on the host system.

  • No authentication or user interaction required.
  • Triggered by a malformed host promise.
  • Results in arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

The vm2 sandbox escape vulnerability could allow attackers to execute arbitrary code on the host system when specific conditions related to host API promises are met. This could occur when an application embeds an API that returns a host-realm Promise, and the sandbox's promise handling is not fully applied to these host Promises, potentially exposing sensitive host objects.

  • Host API interactions within the sandbox.
  • Exploiting host Promise behavior.
  • Arbitrary code execution on the host.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 library is a development dependency, meaning ownership typically falls to the application development team responsible for building and maintaining the software that uses it. The first critical step is for development teams to identify where vm2 is integrated into their codebase and assess the risk based on how the sandbox is used and what sensitive host APIs are exposed.

  • Application development teams own the issue.
  • Verify vm2 usage and sandbox exposure.
  • Plan secure updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library?

vm2 is an npm package used by developers to create a secure, isolated environment for running untrusted JavaScript code. It acts as a sandbox, attempting to prevent the code running inside from accessing or affecting the host system's resources, memory, or sensitive internal objects.

How does this CVE-2026-93606 sandbox escape work?

This vulnerability is a protection mechanism failure categorized as CWE-693. It occurs because the sandbox incorrectly handles 'Promises' that originate from the host rather than the sandbox itself. By manipulating how these promises are constructed, code inside the sandbox can trick the system into leaking a reference to host objects, effectively breaking out of the security boundary.

Do I need to be concerned if my application does not use host APIs?

The vulnerability is specifically triggered by interactions with host-realm Promises. If your sandboxed code does not interact with any APIs provided by the host environment, the specific mechanism required to trigger this escape may not be reachable, even if you are using an affected version of the library.

Is my system exposed if vm2 is in my codebase?

According to Halo Surface Signal, this library is typically a build-time dependency or an internal component, making it very unlikely to be directly reachable from the internet. Your actual risk depends on how your developers have configured the sandbox and whether they have exposed dangerous host-level APIs to the untrusted code.

What should I do to address CVE-2026-93606?

Since vm2 is a development dependency, your primary step is to coordinate with your application development team. They should identify all locations where the library is integrated and update to version 3.12.1 or later, which contains the necessary fixes to properly sanitize Promise interactions and maintain sandbox integrity.

References