CVE-2026-92944 | patriksimek vm2 up to 3.11.6 PromiseThenLookupChain Promise.prototype.finally Symbol.species sandbox
A vulnerability identified as critical has been detected in patriksimek vm2 up to 3.11.6. Affected by this issue is the function Promise.prototype.finally of the component PromiseThenLookupChain. This manipulation of the argument Symbol.species causes sandbox issue.
The identification of this vulnerability is CVE-2026-92944. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More