All verified exploits

CVE-2026-92937 Promise Rejection Sandbox Escape via call/apply Indirection (RCE)

Deterministic critical vm2 Added cve-verified-cve-2026-92937

Detects vm2 sandboxes vulnerable to a promise-rejection escape that yields host remote code execution. When a host-realm promise exposed to the sandbox rejects, vm2 is supposed to rebuild the error and drop every property that references a host object. The gate that triggers the rebuild only recognises a direct call to the host promise then or catch method, so registering the rejection handler through Function.prototype.call or apply skips it entirely. The raw host error then reaches sandbox code intact, and any host object hanging off it becomes a live handle into the host process, which leads straight to arbitrary command execution. This is an incomplete fix for GHSA-m283-3h24-438v. vm2 3.11.6 is affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.

Is your app exploitable through CVE-2026-92937?

Scan your domain free