Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-92939: vm2 allows sandbox code to load attacker native library
CVE-2026-92939 · published 24 days ago
Summary
Versions 3.11.3 to 3.11.6 of the vm2 sandbox let code inside the sandbox call the host's crypto feature and load a malicious native library from the file system. This can let an attacker run any code on the server, even without other dangerous permissions. Update vm2 to version 3.11.7 or later to stop the issue.
What to do
- Update vm2 to version 3.11.7.
- Update patriksimek vm2 to version 3.11.7 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.7 |
| npm | – | vm2 |
>= 3.11.3, <= 3.11.6 Fix: upgrade to 3.11.7
|
Original advisory text
vm2 crypto builtin loads attacker native code through setEngine
vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an untrusted plugin package already written to disk); OpenSSL asks the operating-system dynamic loader to load the file, and the library's constructor executes native code in the host process before engine-symbol validation rejects it. Exploitation requires only the crypto builtin and does not require fs, process, module, child_process, worker_threads, vm, or inspector access, resulting in a sandbox escape and arbitrary native code execution. Fixed in 3.11.7.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-46pr-c5wc-xffx
- https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-native-code-execu...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92939... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92939
- https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483d...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://github.com/advisories/GHSA-46pr-c5wc-xffx
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-114Process Control
Timeline
Published17 Sep 2026
Updated11 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta