All verified exploits

CVE-2026-92956 WebAssembly Streaming-Compile Sandbox Escape (RCE)

Deterministic critical vm2 Added cve-verified-cve-2026-92956

Detects vm2 sandboxes that an attacker can break out of through WebAssembly.compileStreaming or WebAssembly.instantiateStreaming, yielding code execution on the host. On Node.js 26 those two calls hand the sandbox a Promise whose prototype belongs to the host, so vm2's own then/catch overrides and its species hardening never run on it. Guest code plants its own Symbol.species on that Promise and calls finally(), which delivers the raw host-realm error straight into the sandbox; the error's Function constructor then compiles code in the host realm and yields the host process object. We prove it by running a shell command on the host and reading back a product only the target could have computed. No unsafe configuration is needed: a default new VM() with no host objects exposed is enough, so anyone who can submit JavaScript owns the machine. This is a bypass of the earlier WebAssembly JSPI fix. vm2 3.10.1 through 3.11.6 affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.

Is your app exploitable through CVE-2026-92956?

Scan your domain free