CPE
The vm2 sandbox library (v3.11.3-3.11.6) allows attackers to bypass restrictions and execute arbitrary native code in the host process by calling crypto.setEngine() with a path to a malicious dynamic library.