Disclosure summary
## Summary vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) can still be used to terminate the host Node.js process when sandbox code calls a host-realm function that returns a rejected host Promise and then ignores the returned value. This is an incomplete-fix variant of the `GHSA-hw58-p9xv-2mjh` unhandled rejection hardening. The `localPromise` constructor now catches and consumes sandbox-created unhandled rejections, but host Promises returned across the bridge are not marked handled at the bridge boundary. If the sandbox does not attach `.catch()` or `.then(..., onRejected)`, Node's default unhandled rejection behavior terminates the host process. ## Technical Details `lib/setup-sandbox.js` hardens sandbox-created Promises by wrapping the executor and attaching a benign swallow tail: ```js apply(globalPromisePrototypeThen, this, [undefined, localPromiseSwallow]); ``` That only applies to `localPromise` instances created inside the sandbox. Host-returned Promises cross the membrane through the bridge apply path. The bridge wraps callbacks when sandbox code later calls `.then`, `.catch`, or `.finally` on a host Promise: ```js bridge.setHostPromiseSa
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-gjq8-xm47-88rc
Open original source · Updated Oct 05, 2026
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
Source severity: CRITICAL / 9.2
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | vm2 | >= 3.10.0, | 3.11.8 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-05T18:45:48-04:00
MODIFIED 2026-10-05T18:45:49-04:00
INGESTED 2026-10-06T11:45:33-04:00