THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-92944 (CRITICAL 9.8) — vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that r

[NVD] CVE-2026-92944 (CRITICAL 9.8) — vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that r

mednvdPublished 2026-09-17

CVE-2026-92944 CVSS: 9.8 CRITICAL Published: 2026-09-17T14:17:59.623

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled const

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-92944