CPE
A vulnerability in the vm2 sandbox library (CVE-2026-92954) allows sandbox-based code to terminate the host Node.js process by invoking host-realm functions that return unhandled rejected Promises.