Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-92941: vm2 NodeVM can change server's trusted certificates

CVE-2026-92941 · published 23 days ago
Summary

The vm2 sandbox library (versions 3.11.3 to 3.11.6) lets code inside a virtual environment modify the host application's list of trusted certificate authorities. This means an attacker who can run code in the sandbox could make the whole server accept fraudulent HTTPS certificates. Update vm2 to version 3.11.7 or later, or restrict sandbox permissions to block access to TLS and URL functions.

What to do
  • Update vm2 to version 3.11.7.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 >= 3.11.3, <= 3.11.6
Fix: upgrade to 3.11.7
Original advisory text
vm2 NodeVM can replace the host process TLS trust store
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-732Incorrect Permission Assignment for Critical Resource
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92941 · MITRE
Track software like this
Free during beta