CVE-2026-92959 | patriksimek vm2 up to 3.11.7 Async Execution Restriction VM.run/NodeVM.run allowAsync sandbox
A vulnerability marked as problematic has been reported in patriksimek vm2 up to 3.11.7. This impacts the function VM.run/NodeVM.run of the component Async Execution Restriction. This manipulation of the argument allowAsync causes sandbox issue.
The identification of this vulnerability is CVE-2026-92959. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More