CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2
Vulnerability ID: CVE-2026-92941
CVSS Score: 10.0
Published: 2026-10-01
CVE-2026-92941 is a critical sandbox-escape and trust-manipulation vulnerability in the vm2 library (versions 3.11.3 to 3.11.6). This security flaw allows untrusted code executing within a NodeVM sandbox environment to compromise the global TLS trust store of the host Node.js process. By leveraging a design flaw where the host's native 'tls.setDefaultCACertificates' can be executed via a proxy wrapper, combined with a bridge unwrapping bypass in the 'url' module, an attacker can modify the process-wide default root Certificate Authorities. Consequently, all subsequent outbound TLS/HTTPS clients running on the host thread are forced to trust attacker-signed certificates, facilitating transparent Man-in-the-Middle (MitM) attacks. The vulnerability was resolved in version 3.11.7 of vm2 by introducing built-in member-level sanitization before applying read-only proxy wrappers.
TL;DR
A critical flaw in vm2 (3.11.3-3.11.6) allows sandboxed code to bypass isolation and overwrite the global Node.js root CAs, enabling complete Man-in-the-Middle compromise of outbound host HTTPS connections.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-732
- Attack Vector: Network / Code Execution Boundary
- CVSS Score: 10.0
- EPSS Score: 0.00289
- Impact: Process-Wide TLS Trust Store Compromise
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- Applications utilizing the vm2 Node.js library configured with a NodeVM instance that permits access to both 'tls' and 'url' built-in modules.
-
vm2: >= 3.11.3, < 3.11.7 (Fixed in:
3.11.7)
Code Analysis
Commit: aa146a7
Attack Category 40: Host-Authority Builtin Members Survive the Read-Only Wrap
diff --git a/lib/builtin.js b/lib/builtin.js
index f9a12c8..988ddbf 100644
--- a/lib/builtin.js
+++ b/lib/builtin.js
@@ -24,6 +24,19 @@
+function sanitizeTlsModule(mod) {
+ if (typeof mod.setDefaultCACertificates !== 'function') return mod;
+ const copy = Object.assign({}, mod);
+ copy.setDefaultCACertificates = function setDefaultCACertificates() {
+ throw new Error('tls.setDefaultCACertificates is disabled in vm2 sandboxes: it replaces the host process default CA trust store (GHSA-98xx-8mx4-x7cm).');
+ };
+ return copy;
+}
+
+const BUILTIN_MEMBER_SANITIZERS = {
+ __proto__: null,
+ tls: sanitizeTlsModule,
+};
+
Exploit Details
- GitHub Security Advisory: Detailed advisory documentation including proof-of-concept explanation.
Mitigation Strategies
- Upgrade vm2 dependency to version 3.11.7 or later.
- Audit allowed sandbox modules and disable 'tls' or 'url' unless strictly required.
- Migrate the application away from the deprecated vm2 library to secure isolated runtimes.
Remediation Steps:
- Inspect package.json and update vm2 to version 3.11.7.
- If upgrading is not immediate, modify NodeVM options to remove 'tls' and 'url' from the allowed builtin array.
- Initiate migration plans to move sandboxed scripts to separate worker_threads, WebAssembly sandboxes, or containerized environments.
References
- CVE.org Record
- NVD Record
- GitHub Security Advisory
- Official Remediation Commit
- Official Release v3.11.7
Read the full report for CVE-2026-92941 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)