Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-92941: vm2 NodeVM can change server's trusted certificates
CVE-2026-92941 · published 23 days ago
Summary
The vm2 sandbox library (versions 3.11.3 to 3.11.6) lets code inside a virtual environment modify the host application's list of trusted certificate authorities. This means an attacker who can run code in the sandbox could make the whole server accept fraudulent HTTPS certificates. Update vm2 to version 3.11.7 or later, or restrict sandbox permissions to block access to TLS and URL functions.
What to do
- Update vm2 to version 3.11.7.
- Update patriksimek vm2 to version 3.11.7 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.7 |
| npm | – | vm2 |
>= 3.11.3, <= 3.11.6 Fix: upgrade to 3.11.7
|
Original advisory text
vm2 NodeVM can replace the host process TLS trust store
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.
References
- https://www.vulncheck.com/advisories/vm2-3.11.3-before-3.11.7-tls-trust-store-ma...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92941... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92941
- https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm
- https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483d...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://github.com/advisories/GHSA-98xx-8mx4-x7cm
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-732Incorrect Permission Assignment for Critical Resource
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta