CVE-2026-92956 | patriksimek vm2 up to 3.11.6 Sandbox Promise.prototype.finally sandbox

SecurityVulns

A vulnerability described as critical has been identified in patriksimek vm2 up to 3.11.6. This affects the function Promise.prototype.finally of the component Sandbox. Such manipulation leads to sandbox issue.

This vulnerability is uniquely identified as CVE-2026-92956. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More