CVE-2026-92959
published 2026-09-17CVE-2026-92959: vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that…
PriorityP341high7.1CVSS 3.1
AVNACLPRLUINSUCNILAH
EPSS
0.26%
17.6th percentile
vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve, Promise.all, Promise.race, Promise.any, and Promise.allSettled) still assimilate attacker-supplied thenables: native promise resolution performs PromiseResolveThenableJob and invokes the sandboxed code's then method in a microtask without passing through the patched then, so the async restriction is never applied. As a result, sandboxed script can schedule work that runs after VM.run() or NodeVM.run() has returned and outside the configured timeout, continuing to execute after the host believes execution is complete.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | < 3.11.8 | 3.11.8 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM.
ghsa_unreviewed·2026-09-17
CVE-2026-92959 [HIGH] CWE-693 vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM.
vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve, Promise.all, Promise.race, Promise.any, and Promise.allSettled) still assimilate attacker-supplied thenables: native promise resolution performs PromiseResolveThenableJob and invokes the sandboxed code's then method in a microtask without passing through the patched then, so the async restriction is never applied. As a result, sandboxed script can schedule work that runs after VM.run() or NodeVM.run() has returned and outside the configured timeout, continuing to execute after the host believes execution is complete.
Red Hat
vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation
vendor_redhat·2026-09-17·CVSS 7.1
CVE-2026-92959 [HIGH] CWE-358 vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation
vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation
A flaw was found in vm2, a JavaScript sandbox. This vulnerability allows a sandboxed script to bypass security restrictions designed to prevent asynchronous code execution. An attacker can exploit this by using specific Promise methods to assimilate malicious 'thenables,' enabling code to run outside of the intended execution timeout. This can lead to unauthorized resource usage and continued execution after the host system expects the sandbox to be terminated.
Statement: This is an Important vulnerability. The vm2 sandbox, used in Red Hat Ansible Automation Platform and Red Hat Developer Hub, fails to properly enforce asynchronous code execution restrictions. This allows a sandboxed script to execute code out
No detection rules found.
No public exploits indexed.
2026-09-17
Published