DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92939: CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2

CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2

Vulnerability ID: CVE-2026-92939
CVSS Score: 9.9
Published: 2026-10-01

A critical sandbox escape vulnerability in the vm2 library allows sandboxed JavaScript code to bypass containment and execute arbitrary native code on the host process. This occurs when the host's builtin crypto module is exposed to the NodeVM environment. Although vm2 implements a read-only proxy layer to restrict direct modifications to host properties, it does not prevent invocation of host-level functions. By calling the crypto.setEngine API with a path to a malicious native library on disk, an attacker can trigger OpenSSL's dynamic module loader. The host's operating system loader immediately runs the dynamic library's initializers/constructors before verifying engine compatibility, leading to remote code execution in the context of the host process.

TL;DR

The vm2 sandbox allows unauthenticated execution of arbitrary native code via the crypto.setEngine API when the crypto builtin is permitted, resulting in a full host escape.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-114 (Process Control)
  • Attack Vector: Network
  • CVSS v3.1: 9.9 (Critical)
  • EPSS Score: 0.00616
  • Exploit Status: PoC Available
  • KEV Status: Not Listed

Affected Systems

  • Applications utilizing vm2 version 3.11.3 through 3.11.6 with 'crypto' builtin enabled
  • vm2: >= 3.11.3, <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: aa146a7

Sanitize dangerous host members before wrapping with read-only proxy in lib/builtin.js

Mitigation Strategies

  • Upgrade vm2 to version 3.11.7 or higher
  • Disable 'crypto' module in NodeVM configurations if not strictly required
  • Migrate to isolation solutions such as microVMs, WebAssembly, or ephemeral containers

Remediation Steps:

  1. Audit existing codebase for instances of NodeVM initialization.
  2. Ensure the 'require.builtin' configuration array does not contain 'crypto'.
  3. Update package.json dependencies to reference 'vm2': '^3.11.7'.
  4. Rebuild and redeploy application containers or execution environments.

References


Read the full report for CVE-2026-92939 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)