<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vm2_project:vm2:3.10.0:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avm2_projectvm23.10.0node.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:42:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avm2_projectvm23.10.0node.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>vm2 Denial of Service via Host-Returned Promise Rejection</title><link>https://feed.craftedsignal.io/briefs/2026-10-vm2-dos/</link><pubDate>Tue, 06 Oct 2026 00:42:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-vm2-dos/</guid><description>A vulnerability in the vm2 sandbox library (CVE-2026-92954) allows sandbox-based code to terminate the host Node.js process by invoking host-realm functions that return unhandled rejected Promises.</description><content:encoded><![CDATA[<p>The vm2 sandbox library (versions 3.10.0 through 3.11.7) contains an incomplete fix for asynchronous rejection hardening, leading to a Denial of Service (DoS) vulnerability. When a sandbox executes code that calls a host-realm function returning a rejected Promise, the bridge mechanism fails to mark the host Promise as 'handled'. If the sandbox code does not explicitly attach a catch block to the returned Promise, the resulting unhandled rejection propagates to the host Node.js environment.</p>
<p>Node.js default behavior for unhandled rejections is to terminate the process, allowing an attacker to crash the entire application host. This vulnerability is particularly critical for multi-tenant environments, notebook workers, or plugin hosts that expose async host APIs or allow the 'events' builtin in NodeVM. This is a regression of hardening efforts originally introduced in GHSA-hw58-p9xv-2mjh and persists across major Node.js versions, including v16, v18, v20, v22, v24, and v25.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains the ability to execute arbitrary code within a vm2 sandbox environment.</li>
<li>Attacker identifies an exposed host-realm function (e.g., via <code>sandbox</code> configuration) that returns a Promise.</li>
<li>Attacker invokes the host function to obtain a host-realm Promise instance.</li>
<li>Alternatively, in <code>NodeVM</code> configurations, the attacker utilizes the <code>events</code> builtin to call <code>events.once()</code>.</li>
<li>Attacker triggers a rejection on the host-side object or event emitter.</li>
<li>The bridge returns the rejected Promise to the sandbox without attaching a defensive <code>.catch()</code> or rejection handler.</li>
<li>Attacker ignores the returned value, leaving the host Promise unhandled.</li>
<li>The host Node.js runtime detects the unhandled rejection and terminates the parent process, causing a DoS.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the immediate termination of the host Node.js process. This impacts any multi-tenant system, web service, or background worker utilizing vm2 for code isolation. Because the payload can be replayed after a process restart, automated recovery policies are ineffective against this primitive.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Immediate mitigation is required for all applications using vm2.</p>
<ul>
<li>Implement a process-level <code>unhandledRejection</code> handler in the host Node.js application to catch and swallow rejections originating from the vm2 sandbox, preventing process termination.</li>
<li>Audit all <code>NodeVM</code> configurations; disable the <code>events</code> builtin if it is not strictly required for sandbox functionality.</li>
<li>Restrict the exposure of host-realm functions that return Promises to sandboxed environments.</li>
<li>Monitor logs for the <code>node:internal/process/promises</code> uncaught exception errors to identify potential exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>sandbox-escape</category><category>nodejs</category></item></channel></rss>