Arbitrary Native Code Execution in vm2 via crypto.setEngine
The vm2 sandbox library (v3.11.3-3.11.6) allows attackers to bypass restrictions and execute arbitrary native code in the host process by calling crypto.setEngine() with a path to a malicious dynamic library.
CVE search metadata
CVE search record: CVE-2026-92939. Severity: critical. CVSS: 9.9. EPSS: 0.62%. KEV: no. Product: vm2 (3.11.3 - 3.11.6). Brief: Arbitrary Native Code Execution in vm2 via crypto.setEngine. Brief link: https://feed.craftedsignal.io/briefs/2026-10-vm2-crypto-rce/
The vm2 library, specifically versions 3.11.3 through 3.11.6, contains a critical vulnerability (CVE-2026-92939) that permits sandbox escape and arbitrary native code execution. The vulnerability arises from how vm2 exposes Node.js built-in modules to the sandboxed environment. While vm2 uses a read-only proxy to prevent modification of module properties, it does not restrict the authority of callable exports.
The crypto.setEngine() function is exposed to the sandbox when crypto is an allowed builtin. This function accepts a filesystem path and instructs OpenSSL to load the referenced dynamic library as a cryptographic engine. Crucially, the operating system's dynamic loader executes the library's constructor logic before OpenSSL performs any validation of the library's validity as a cryptographic engine. An attacker providing a malicious package can place a dynamic library on disk and trigger its execution from the sandbox, gaining the privileges of the host process regardless of other sandboxing restrictions.
Attack Chain
- Attacker crafts a malicious package containing a compiled native dynamic library (e.g., .so or .dylib).
- Attacker provides the package to an application that processes untrusted plugins (e.g., code runner, automation platform).
- The application saves the package contents to the local filesystem.
- The application initializes a
NodeVMinstance, granting access to thecryptobuiltin but restricting other modules. - The attacker's JavaScript code within the
NodeVMcallscrypto.setEngine(pathToBundledLibrary). - vm2 forwards the call to the host-realm
crypto.setEnginefunction. - The host process loads the attacker's dynamic library via the operating system's native loader.
- The library's constructor executes arbitrary native code within the host process, achieving full system compromise.
Impact
This vulnerability allows for a complete sandbox escape, granting the attacker the operating-system identity and permissions of the host Node.js process. Potential impact includes unauthorized access to environment variables, application secrets, credentials, and internal data. Attackers can modify application code, establish persistence, access internal network services, steal data from other tenants sharing the same process, or perform any action permitted to the host user account.
Recommendation
Prioritize upgrading all instances of the affected vm2 package.
- Upgrade vm2 to a version beyond 3.11.6 immediately, as there are no configuration-based mitigations that safely allow the
cryptobuiltin while preventing this attack vector. - Audit all applications utilizing
vm2forNodeVMconfigurations that grant access to thecryptobuiltin, specifically in multi-tenant or untrusted plugin scenarios. - Implement process-level sandboxing (e.g., containerization, gVisor, or restricted service accounts) to limit the potential impact of native code execution if an application remains vulnerable.
Immediate actions
Patch vm2 to 3.11.7 or later
Mitigations
Upgrade vm2 to 3.11.7 or later
CVE-2026-92939