在 vm2 3.12.2 版本之前,sandbox-to-host(沙箱到主机)的 construct 陷阱未正确应用主机侧的 Promise 拒绝处理机制。在 BaseHandler 中,apply 陷阱会对返回值调用 ,但相邻的 construct 路径仅返回 的结果,而未进行相同的清理处理。如果嵌入程序暴露了一个可构造的主机函数,且其构造函数返回一个原生拒绝态(rejected)的 Promise,那么通过 执行的不受信任脚本可以使用 关键字调用该函数并忽略返回结果;此时,被拒绝的主机 Promise 会在未
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| patriksimek | vm2 | 0 ~ 3.12.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100721 | 9.0 CRITICAL | vm2 before 3.12.2 Authorization Bypass via Custom Resolver |
| CVE-2026-100723 | 7.5 HIGH | vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool |
No comments yet