Node.js Crypto Module Vulnerability in vm2 by Patric Simek
CVE-2026-92939

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92939?

The vulnerability in vm2 versions 3.11.3 through 3.11.6 allows the Node.js crypto module to be exposed to a NodeVM sandbox. When the crypto builtin is enabled, it can be exploited by executing commands that lead to a sandbox escape, permitting an attacker to use crypto.setEngine() with a custom native library. This library can be loaded using OpenSSL's dynamic loader, enabling potential execution of malicious code within the host environment. The issue is resolved in version 3.11.7.

Affected Version(s)

vm2 3.11.3 < 3.11.7

vm2 3.11.7

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Forrof
.