OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92939

CRITICAL · CVSS 9.9 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the vm2 library versions 3.11.3 to 3.11.6, allowing sandboxed JavaScript to execute arbitrary native code through the host Node.js crypto module when the crypto builtin is enabled. This critical flaw can lead to a sandbox escape, enabling attackers to load and execute malicious native libraries, posing significant risks to system integrity and security. Organizations using affected versions of vm2, especially those relying on Node.js for secure environments, should prioritize upgrading to version 3.11.7 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92939
Severity
CRITICAL
CVSS
9.9
EPSS
0.62%
Java OpenSSL

Original NVD Description

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an untrusted plugin package already written to disk); OpenSSL asks the operating-system dynamic loader to load the file, and the library's constructor executes native code in the host process before engine-symbol validation rejects it. Exploitation requires only the crypto builtin and does not require fs, process, module, child_process, worker_threads, vm, or inspector access, resulting in a sandbox escape and arbitrary native code execution. Fixed in 3.11.7.