Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. vm2
  4. ›
  5. CVE-2026-92942

CVE-2026-92942: vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)

October 5, 2026

vm2’s VM({ timeout }) option is documented and relied upon as the mechanism that bounds how long sandboxed code may execute. In the current implementation, the timeout only wraps the single synchronous call to VM#run() (via doWithTimeout → this._runScript(script) in lib/vm.js). It does not, and structurally cannot, bound code that the V8 engine itself schedules to run after that call has already returned.

FinalizationRegistry and WeakRef are exposed to sandboxed code completely unmodified — they are not present anywhere in lib/setup-sandbox.js’s list of specially-wrapped/hardened globals (only WeakMap, Promise, Proxy, Reflect, etc. receive hardening there). Sandboxed code can register a FinalizationRegistry callback against an object it creates and immediately drops. VM#run() returns normally, well within the configured timeout, because registration is instant. At some later point — determined entirely by the V8 garbage collector, and forceable on demand by the host process (e.g. under memory pressure, or via --expose-gc) — the engine invokes the sandboxed cleanup callback directly. This invocation is not mediated by doWithTimeout, Script.runInContext({timeout}), or any other vm2 accounting mechanism, because it isn’t a new call to VM#run() at all — it’s the GC’s own native callback-invocation path.

References

  • github.com/advisories/GHSA-r4fx-v8hh-22mv
  • github.com/patriksimek/vm2/commit/fe2fcca2a1e693548993eccc624489dc4cb586b4
  • github.com/patriksimek/vm2/releases/tag/v3.11.7
  • github.com/patriksimek/vm2/security/advisories/GHSA-r4fx-v8hh-22mv
  • nvd.nist.gov/vuln/detail/CVE-2026-92942
  • www.vulncheck.com/advisories/vm2-before-3.11.7-timeout-bypass-via-finalizationregistry

Code Behaviors & Features

Detect and mitigate CVE-2026-92942 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.11.7

Fixed versions

  • 3.11.7

Solution

Upgrade to version 3.11.7 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-841: Improper Enforcement of Behavioral Workflow

Source file

npm/vm2/CVE-2026-92942.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 06 Oct 2026 12:26:32 +0000.