GHSA-6jgm-4w45-vh8jCritical· 9.9▾ MidnightDuplicate Advisory: vm2 crypto builtin loads attacker native code through setEngine
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-46pr-c5wc-xffx. This link is maintained to preserve external references.
vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an untrusted plugin package already written to disk); OpenSSL asks the operating-system dynamic loader to load the file, and the library's constructor executes native code in the host process before engine-symbol validation rejects it. Exploitation requires only the crypto builtin and does not require fs, process, module, child_process, worker_threads, vm, or inspector access, resulting in a sandbox escape and arbitrary native code execution. Fixed in 3.11.7.
vm2 >= 3.11.3, <= 3.11.6Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92939Critical· 9.9vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed
GHSA-xq74-c7jx-8w5jCritical· 10.0Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store
GHSA-8mvv-mcc3-xwhhLow· 4.2Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
GHSA-hwr5-cm8v-c76qCritical· 9.8Duplicate Advisory: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
GHSA-3f84-vwv5-r42gCritical· 10.0Duplicate Advisory: vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
GHSA-m7cq-7f2q-f9fhCritical· 9.9Duplicate Advisory: vm2 3.11.6 allows a sandboxed plugin to execute native code through `node:sqlite`