Detects vm2 sandboxes vulnerable to a Promise.prototype.finally() escape that yields host remote code execution. vm2 installs its Promise then/catch wrappers by direct property assignment; on Node.js 26 / V8 14.6 that path leaves the PromiseThenLookupChain protector valid, so finally() takes a fast path to the original native then and bypasses vm2's resetPromiseSpecies hardening. An attacker-controlled constructor Symbol.species then drives a native promise reaction that delivers a raw host-realm error whose constructor.constructor is the host Function constructor, reaching the host process and arbitrary code execution. Anyone who can submit JavaScript to the sandbox owns the host. vm2 3.10.2 through 3.11.6 affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.
Is your app exploitable through CVE-2026-92944?
Scan your domain free