{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vm2-3.10.0-3.11.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vm2_project:vm2:3.10.0:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-92954"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vm2 (3.10.0-3.11.7)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","sandbox-escape","nodejs"],"_cs_type":"advisory","_cs_vendors":["Node.js Foundation"],"content_html":"\u003cp\u003eThe vm2 sandbox library (versions 3.10.0 through 3.11.7) contains an incomplete fix for asynchronous rejection hardening, leading to a Denial of Service (DoS) vulnerability. When a sandbox executes code that calls a host-realm function returning a rejected Promise, the bridge mechanism fails to mark the host Promise as 'handled'. If the sandbox code does not explicitly attach a catch block to the returned Promise, the resulting unhandled rejection propagates to the host Node.js environment.\u003c/p\u003e\n\u003cp\u003eNode.js default behavior for unhandled rejections is to terminate the process, allowing an attacker to crash the entire application host. This vulnerability is particularly critical for multi-tenant environments, notebook workers, or plugin hosts that expose async host APIs or allow the 'events' builtin in NodeVM. This is a regression of hardening efforts originally introduced in GHSA-hw58-p9xv-2mjh and persists across major Node.js versions, including v16, v18, v20, v22, v24, and v25.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains the ability to execute arbitrary code within a vm2 sandbox environment.\u003c/li\u003e\n\u003cli\u003eAttacker identifies an exposed host-realm function (e.g., via \u003ccode\u003esandbox\u003c/code\u003e configuration) that returns a Promise.\u003c/li\u003e\n\u003cli\u003eAttacker invokes the host function to obtain a host-realm Promise instance.\u003c/li\u003e\n\u003cli\u003eAlternatively, in \u003ccode\u003eNodeVM\u003c/code\u003e configurations, the attacker utilizes the \u003ccode\u003eevents\u003c/code\u003e builtin to call \u003ccode\u003eevents.once()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a rejection on the host-side object or event emitter.\u003c/li\u003e\n\u003cli\u003eThe bridge returns the rejected Promise to the sandbox without attaching a defensive \u003ccode\u003e.catch()\u003c/code\u003e or rejection handler.\u003c/li\u003e\n\u003cli\u003eAttacker ignores the returned value, leaving the host Promise unhandled.\u003c/li\u003e\n\u003cli\u003eThe host Node.js runtime detects the unhandled rejection and terminates the parent process, causing a DoS.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate termination of the host Node.js process. This impacts any multi-tenant system, web service, or background worker utilizing vm2 for code isolation. Because the payload can be replayed after a process restart, automated recovery policies are ineffective against this primitive.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eImmediate mitigation is required for all applications using vm2.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement a process-level \u003ccode\u003eunhandledRejection\u003c/code\u003e handler in the host Node.js application to catch and swallow rejections originating from the vm2 sandbox, preventing process termination.\u003c/li\u003e\n\u003cli\u003eAudit all \u003ccode\u003eNodeVM\u003c/code\u003e configurations; disable the \u003ccode\u003eevents\u003c/code\u003e builtin if it is not strictly required for sandbox functionality.\u003c/li\u003e\n\u003cli\u003eRestrict the exposure of host-realm functions that return Promises to sandboxed environments.\u003c/li\u003e\n\u003cli\u003eMonitor logs for the \u003ccode\u003enode:internal/process/promises\u003c/code\u003e uncaught exception errors to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:42:52Z","date_published":"2026-10-06T00:42:52Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vm2-dos/","summary":"A vulnerability in the vm2 sandbox library (CVE-2026-92954) allows sandbox-based code to terminate the host Node.js process by invoking host-realm functions that return unhandled rejected Promises.","title":"vm2 Denial of Service via Host-Returned Promise Rejection","url":"https://feed.craftedsignal.io/briefs/2026-10-vm2-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Vm2 (3.10.0-3.11.7)","version":"https://jsonfeed.org/version/1.1"}