Sceawere

Vulnerability Detail

CVE-2026-100722UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

vm2 Sandbox Host Promise Escape

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
1d ago
Vendor
patriksimek
Product
vm2
Attack Type
Uncaught Exception
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.construct without the same sanitization. If an embedder exposes a constructable host function whose constructor returns a native rejected Promise, an untrusted script executed via VM.run can invoke it with `new` and ignore the result; the rejected host Promise crosses the bridge unhandled and, under Node's strict unhandled-rejection policy, is promoted to an uncaught exception that terminates the host process.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-09-27T02:17:18.817Z",
  "pubdate": "2026-09-27T02:17:18.817Z",
  "executiveSummary": "The vulnerability resides in the sandbox-to-host construct trap implementation within the vm2 library, specifically in versions prior to 3.12.2.\nThe flaw allows an untrusted script to trigger an uncaught exception in the host process, leading to a denial-of-service (DoS) condition.\nThis occurs because the construct path in BaseHandler fails to sanitize returned objects, specifically neglecting to apply markHostPromiseHandled() to host-originated rejected Promises.\nBy invoking a constructable host function that returns a rejected Promise, an attacker can bypass vm2's security sandbox, causing the host's Node.js runtime to terminate due to its strict unhandled-rejection policy.\nThe vulnerability requires the exposure of a constructable host function to the sandboxed environment.\nThis presents a high-risk security flaw for applications relying on vm2 for secure code isolation, as a successful exploit compromises the availability of the entire host application instance.",
  "technicalDetails": "The vulnerability is located in the vm2 sandbox's Proxy mechanism, specifically within the BaseHandler class which manages the interaction between the guest (sandboxed) environment and the host environment.\nIn the apply trap for function calls, vm2 correctly implements markHostPromiseHandled() to ensure that any host-originated Promises returned to the sandbox are properly handled, preventing unhandled rejections from propagating back to the host process.\nHowever, the construct trap, responsible for handling the 'new' keyword on proxied objects, returns the result of Reflect.construct directly without performing the same Promise sanitization logic.\nThe root cause is an implementation inconsistency: the construct trap fails to identify if a constructor returns a host-side native Promise that might be in a rejected state.\nThe exploitation flow proceeds as follows: First, a host application exposes a constructable function to the vm2 sandbox environment. Second, an attacker executing code via VM.run invokes this function using the 'new' keyword. Third, the host function is engineered to return a rejected native Promise. Fourth, because the construct trap lacks the markHostPromiseHandled() logic, the rejected Promise crosses the sandbox bridge unhandled. Fifth, the Node.js runtime, operating under a strict unhandled-rejection policy, perceives this as an unhandled Promise rejection.\nThis results in the rejection being promoted to an uncaught exception. Because the exception occurs within the host's context but originates from an external trigger, it typically results in the immediate termination of the host process, effectively causing a denial of service.\nThe vulnerability impacts all versions of vm2 before 3.12.2. No specific authentication or privilege escalation is required within the guest context, provided the attacker has the ability to execute arbitrary code via the VM.run() interface.\nThe attack is highly effective in environments where the host application passes constructable objects or functions into the sandbox, as the attacker does not need to bypass the sandbox isolation mechanism itself, but rather exploits the bridge's failure to handle Promise states correctly."
}
CVE-2026-100722: vm2 Sandbox Host Promise Escape (MEDIUM Severity, CVSS: 6.8) | Sceawere