CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2
Vulnerability ID: CVE-2026-92939
CVSS Score: 9.9
Published: 2026-10-01
A critical sandbox escape vulnerability in the vm2 library allows sandboxed JavaScript code to bypass containment and execute arbitrary native code on the host process. This occurs when the host's builtin crypto module is exposed to the NodeVM environment. Although vm2 implements a read-only proxy layer to restrict direct modifications to host properties, it does not prevent invocation of host-level functions. By calling the crypto.setEngine API with a path to a malicious native library on disk, an attacker can trigger OpenSSL's dynamic module loader. The host's operating system loader immediately runs the dynamic library's initializers/constructors before verifying engine compatibility, leading to remote code execution in the context of the host process.
TL;DR
The vm2 sandbox allows unauthenticated execution of arbitrary native code via the crypto.setEngine API when the crypto builtin is permitted, resulting in a full host escape.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-114 (Process Control)
- Attack Vector: Network
- CVSS v3.1: 9.9 (Critical)
- EPSS Score: 0.00616
- Exploit Status: PoC Available
- KEV Status: Not Listed
Affected Systems
- Applications utilizing vm2 version 3.11.3 through 3.11.6 with 'crypto' builtin enabled
-
vm2: >= 3.11.3, <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: aa146a7
Sanitize dangerous host members before wrapping with read-only proxy in lib/builtin.js
Mitigation Strategies
- Upgrade vm2 to version 3.11.7 or higher
- Disable 'crypto' module in NodeVM configurations if not strictly required
- Migrate to isolation solutions such as microVMs, WebAssembly, or ephemeral containers
Remediation Steps:
- Audit existing codebase for instances of NodeVM initialization.
- Ensure the 'require.builtin' configuration array does not contain 'crypto'.
- Update package.json dependencies to reference 'vm2': '^3.11.7'.
- Rebuild and redeploy application containers or execution environments.
References
- NVD - CVE-2026-92939 Detail
- GitHub Security Advisory GHSA-46pr-c5wc-xffx
- VulnCheck Advisory for CVE-2026-92939
Read the full report for CVE-2026-92939 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)