CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100722

MEDIUMCVSS 6.8NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.construct without the same sanitization. If

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100722 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100722

MEDIUMCVSS 6.8NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.construct without the same sanitization. If

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]