vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information disclosure from the sandbox.
References
Configurations
No configuration.
History
17 Sep 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/patriksimek/vm2/security/advisories/GHSA-x965-fc75-jpqh - |
17 Sep 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-17 14:17
Updated : 2026-09-17 15:17
NVD link : CVE-2026-92934
Mitre link : CVE-2026-92934
CVE.ORG link : CVE-2026-92934
JSON object : View
Products Affected
No product.
CWE
CWE-693
Protection Mechanism Failure
