Junglewise Threat Intelligence

CVE-2026-93604: vm2 sandbox escape via crypto.setFips exposure

CVE-2026-93604 · Severity: high · CVSS 7.2 · Published 2026-09-18

Technologies: Patrick Simek Vm2.

Executive brief

vm2 is a sandboxing library that isolates untrusted JavaScript code. When configured to allowlist the Node.js crypto module, vm2 fails to properly restrict the crypto.setFips() function, allowing guest code to change the host process's FIPS cryptographic mode. This crosses the sandbox boundary and modifies cryptographic security settings for trusted host code, potentially causing algorithm-enforcement failures and compromising the integrity of host security configuration.

Technical details

This is an improper access control vulnerability (CWE-284) in vm2's builtin module sanitizer. The sanitizeCryptoModule function in lib/builtin.js replaces crypto.setEngine but fails to neutralize crypto.setFips(), which is a process-wide state mutation. Although the module is exposed through a readonly wrapper that prevents property replacement, the wrapper does not localize side effects of forwarded host functions. An attacker who can supply JavaScript to a NodeVM with require.builtin: ['crypto'] configured can call crypto.setFips(1) to enable FIPS mode on the host process, which is then observed by trusted host code via crypto.getFips(). No authentication, network access, or user interaction is required beyond code execution within the NodeVM itself. The vulnerability is fixed in vm2 3.12.1.

Affected products

  • Patrick Simek vm2 through 3.12.0

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: vm2 3.12.1 released

References