Sandbox Escape Vulnerability in vm2 by Patric Simek
CVE-2026-92934

9.5CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92934?

vm2 versions prior to 3.11.8 contain an incomplete fix for the sanitization of Error.cause, leading to a potential sandbox escape. Attackers can exploit this vulnerability by bypassing cycle detection in the handleException method, allowing them to manipulate host-wrapped AggregateError objects. This flaw enables unauthorized access to unsanitized host proxies within the errors array, resulting in the capability for full remote code execution and disclosing process information from the sandboxed environment.

Affected Version(s)

vm2 0 < 3.11.8

vm2 3.11.8

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
maru1009
.