CVE-2026-93606 | patriksimek vm2 up to 3.12.0 Bridge lib/bridge.js hostPromiseSanitizeReject privileges management

SecurityVulns

A vulnerability classified as critical has been found in patriksimek vm2 up to 3.12.0. This affects the function hostPromiseSanitizeReject of the file lib/bridge.js of the component Bridge. This manipulation causes improper privilege management.

This vulnerability is tracked as CVE-2026-93606. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More