Executive brief
vm2 is a Node.js library used to safely run untrusted JavaScript code in a sandboxed environment, commonly used in plugin systems and multi-tenant code runners. When the crypto module is allowed in the sandbox, an attacker can exploit the crypto.setEngine() function to load a malicious native library from disk, bypassing all sandbox restrictions and executing arbitrary code with the host process's full system privileges and access to all files and credentials.
Technical details
The vulnerability is a sandbox escape caused by improper isolation of the Node.js crypto module. When crypto is exposed to a NodeVM sandbox through a read-only proxy, the proxy's callable functions still execute in the host realm with full host authority. An attacker can call crypto.setEngine(path) with a path to an attacker-supplied native library (e.g., bundled in an untrusted plugin package already on disk); OpenSSL dynamically loads the library and executes its constructor in the host process before validating whether it is a genuine cryptographic engine. This allows arbitrary native code execution without requiring fs, process, or other dangerous builtins. Exploitation requires only the crypto builtin to be allowed and affects vm2 versions 3.11.3 through 3.11.6. The vulnerability has been fixed in version 3.11.7.
Affected products
- Patriksimek vm2 3.11.3 through 3.11.6
Timeline
- 2026-08-24: disclosed: GitHub Security Advisory (GHSA-46pr-c5wc-xffx) published
- 2026-09-17: advisory: CVE-2026-92939 published
- 2026: patched: Fixed in vm2 3.11.7