SB2026090407 - Multiple vulnerabilities in vm2



SB2026090407 - Multiple vulnerabilities in vm2

Published: September 4, 2026 Updated: September 22, 2026

Security Bulletin ID SB2026090407
CSH Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 75% Medium 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Improper Control of Dynamically-Managed Code Resources (CVE-ID: CVE-2026-93603)

CWE-ID: CWE-913 - Improper Control of Dynamically-Managed Code Resources

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the host.

The vulnerability exists due to improper handling of nullish this receivers in the BaseHandler apply trap in lib/bridge.js when sandboxed code invokes an exposed non-strict host function without a receiver. A remote attacker can invoke the function to obtain the host global object and execute commands on the host.

Exploitation requires the embedder to expose a non-strict host function to the sandbox; strict-mode and ESM functions are unaffected.


2) Improper access control (CVE-ID: CVE-2026-93604)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to alter host process cryptographic configuration and cause a denial of service.

The vulnerability exists due to improper access control in the NodeVM crypto sanitizer when executing untrusted JavaScript in a NodeVM with the crypto builtin allowlisted. A remote attacker can call crypto.setFips to alter host process cryptographic configuration and cause a denial of service.

Exploitation depends on a Node.js/OpenSSL build where crypto.setFips is functional.


3) Protection mechanism failure (CVE-ID: CVE-2026-93605)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands on the host.

The vulnerability exists due to a protection mechanism failure in the NodeVM dangerous built-ins denylist when processing sandboxed scripts with all built-in modules allowed. A remote attacker can run a sandboxed script that requires the child_process module to execute arbitrary commands on the host.

The issue also occurs when child_process is explicitly allowed.


4) Protection mechanism failure (CVE-ID: CVE-2026-93606)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to protection mechanism failure in the vm2 bridge's host-realm Promise rejection sanitizer when handling a host-realm Promise rejection without an onRejected handler. A remote attacker can hijack Symbol.species on the host Promise and invoke then without an onRejected handler to execute arbitrary code.

Exploitation requires the embedder to expose a host-realm Promise that rejects with a host-pivotable value.


Remediation

Install update from vendor's website.