SB2026090407 - Multiple vulnerabilities in vm2
Published: September 4, 2026 Updated: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Improper Control of Dynamically-Managed Code Resources (CVE-ID: CVE-2026-93603)
CWE-ID: CWE-913 - Improper Control of Dynamically-Managed Code Resources
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the host.
The vulnerability exists due to improper handling of nullish this receivers in the BaseHandler apply trap in lib/bridge.js when sandboxed code invokes an exposed non-strict host function without a receiver. A remote attacker can invoke the function to obtain the host global object and execute commands on the host.
Exploitation requires the embedder to expose a non-strict host function to the sandbox; strict-mode and ESM functions are unaffected.
2) Improper access control (CVE-ID: CVE-2026-93604)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to alter host process cryptographic configuration and cause a denial of service.
The vulnerability exists due to improper access control in the NodeVM crypto sanitizer when executing untrusted JavaScript in a NodeVM with the crypto builtin allowlisted. A remote attacker can call crypto.setFips to alter host process cryptographic configuration and cause a denial of service.
Exploitation depends on a Node.js/OpenSSL build where crypto.setFips is functional.
3) Protection mechanism failure (CVE-ID: CVE-2026-93605)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary commands on the host.
The vulnerability exists due to a protection mechanism failure in the NodeVM dangerous built-ins denylist when processing sandboxed scripts with all built-in modules allowed. A remote attacker can run a sandboxed script that requires the child_process module to execute arbitrary commands on the host.
The issue also occurs when child_process is explicitly allowed.
4) Protection mechanism failure (CVE-ID: CVE-2026-93606)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to protection mechanism failure in the vm2 bridge's host-realm Promise rejection sanitizer when handling a host-realm Promise rejection without an onRejected handler. A remote attacker can hijack Symbol.species on the host Promise and invoke then without an onRejected handler to execute arbitrary code.
Exploitation requires the embedder to expose a host-realm Promise that rejects with a host-pivotable value.
Remediation
Install update from vendor's website.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-j89j-5m6r-cr2q
- https://github.com/patriksimek/vm2/security/advisories/GHSA-x3v6-43hc-82mc
- https://github.com/patriksimek/vm2/blob/525961bf631b4a5a776e1eb620bcadad4438b130/lib/builtin.js#L254-L259
- https://github.com/patriksimek/vm2/security/advisories/GHSA-pq68-rvw4-xp4r
- https://github.com/patriksimek/vm2/security/advisories/GHSA-6454-5x88-m6jw