CVE-2026-100722: vm2 before 3.12.2 Host Process Termination via Construct Trap

Published Sep 27, 2026
·
Updated

vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.construct without the same sanitization. If an embedder exposes a constructable host function whose constructor returns a native rejected Promise, an untrusted script executed via VM.run can invoke it with new and ignore the result; the rejected host Promise crosses the bridge unhandled and, under Node's strict unhandled-rejection policy, is promoted to an uncaught exception that terminates the host process.

Affected Software

1 affected component
npm/vm2<3.12.2

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are actually exposed to host-process termination?

Exposure requires an application using vm2 before 3.12.2 that executes untrusted code with VM.run and exposes a constructable host function to that code. The exposed constructor must be capable of returning a native rejected Promise.

2

What must an attacker do to trigger the issue?

An attacker must be able to run an untrusted script in the vm2 sandbox and invoke the exposed host function with new. The script can ignore the constructor result, leaving the rejected host Promise unhandled across the sandbox-to-host bridge.

3

Does exploitation depend on Node.js runtime policy?

Yes. The described host-process termination occurs when Node uses a strict unhandled-rejection policy, under which the unhandled rejected Promise is promoted to an uncaught exception.

4

How can I assess whether my application is affected?

Check whether your application uses a vm2 version before 3.12.2, calls VM.run with untrusted input, and exposes constructable host functions into the sandbox. Review whether any such constructor can return a native rejected Promise and whether the Node runtime uses strict unhandled-rejection handling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203