GitHub Security Advisories
5 min
GitHub Security Advisories
CVE-2026-92954: vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
## Summary vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) can still be used to terminate the host Node.js process when sandbox code calls a host-realm function that returns a rejected...