Sandbox Escape Vulnerability in vm2 by Patric Simek
CVE-2026-92934
9.5CRITICAL
What is CVE-2026-92934?
vm2 versions prior to 3.11.8 contain an incomplete fix for the sanitization of Error.cause, leading to a potential sandbox escape. Attackers can exploit this vulnerability by bypassing cycle detection in the handleException method, allowing them to manipulate host-wrapped AggregateError objects. This flaw enables unauthorized access to unsanitized host proxies within the errors array, resulting in the capability for full remote code execution and disclosing process information from the sandboxed environment.
Affected Version(s)
vm2 0 < 3.11.8
vm2 3.11.8
