CVE-2026-100722: vm2 before 3.12.2 Host Process Termination via Construct Trap
vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.construct without the same sanitization. If an embedder exposes a constructable host function whose constructor returns a native rejected Promise, an untrusted script executed via VM.run can invoke it with new and ignore the result; the rejected host Promise crosses the bridge unhandled and, under Node's strict unhandled-rejection policy, is promoted to an uncaught exception that terminates the host process.
Affected Software
Event History
Frequently Asked Questions
Which deployments are actually exposed to host-process termination?
Exposure requires an application using vm2 before 3.12.2 that executes untrusted code with VM.run and exposes a constructable host function to that code. The exposed constructor must be capable of returning a native rejected Promise.
What must an attacker do to trigger the issue?
An attacker must be able to run an untrusted script in the vm2 sandbox and invoke the exposed host function with new. The script can ignore the constructor result, leaving the rejected host Promise unhandled across the sandbox-to-host bridge.
Does exploitation depend on Node.js runtime policy?
Yes. The described host-process termination occurs when Node uses a strict unhandled-rejection policy, under which the unhandled rejected Promise is promoted to an uncaught exception.
How can I assess whether my application is affected?
Check whether your application uses a vm2 version before 3.12.2, calls VM.run with untrusted input, and exposes constructable host functions into the sandbox. Review whether any such constructor can return a native rejected Promise and whether the Node runtime uses strict unhandled-rejection handling.