Improper Control of Dynamically-Managed Code Resources in vm2 - CVE-2026-93603
Published: September 4, 2026 / Updated: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the host.
The vulnerability exists due to improper handling of nullish this receivers in the BaseHandler apply trap in lib/bridge.js when sandboxed code invokes an exposed non-strict host function without a receiver. A remote attacker can invoke the function to obtain the host global object and execute commands on the host.
Exploitation requires the embedder to expose a non-strict host function to the sandbox; strict-mode and ESM functions are unaffected.