{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopenjs_foundationvm2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openjs_foundation:vm2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-92939"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vm2 (3.11.3 - 3.11.6)"],"_cs_severities":["critical"],"_cs_tags":["sandbox-escape","remote-code-execution","nodejs","supply-chain"],"_cs_type":"advisory","_cs_vendors":["OpenJS Foundation"],"content_html":"\u003cp\u003eThe vm2 library, specifically versions 3.11.3 through 3.11.6, contains a critical vulnerability (CVE-2026-92939) that permits sandbox escape and arbitrary native code execution. The vulnerability arises from how vm2 exposes Node.js built-in modules to the sandboxed environment. While vm2 uses a read-only proxy to prevent modification of module properties, it does not restrict the authority of callable exports.\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003ecrypto.setEngine()\u003c/code\u003e function is exposed to the sandbox when \u003ccode\u003ecrypto\u003c/code\u003e is an allowed builtin. This function accepts a filesystem path and instructs OpenSSL to load the referenced dynamic library as a cryptographic engine. Crucially, the operating system's dynamic loader executes the library's constructor logic before OpenSSL performs any validation of the library's validity as a cryptographic engine. An attacker providing a malicious package can place a dynamic library on disk and trigger its execution from the sandbox, gaining the privileges of the host process regardless of other sandboxing restrictions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious package containing a compiled native dynamic library (e.g., .so or .dylib).\u003c/li\u003e\n\u003cli\u003eAttacker provides the package to an application that processes untrusted plugins (e.g., code runner, automation platform).\u003c/li\u003e\n\u003cli\u003eThe application saves the package contents to the local filesystem.\u003c/li\u003e\n\u003cli\u003eThe application initializes a \u003ccode\u003eNodeVM\u003c/code\u003e instance, granting access to the \u003ccode\u003ecrypto\u003c/code\u003e builtin but restricting other modules.\u003c/li\u003e\n\u003cli\u003eThe attacker's JavaScript code within the \u003ccode\u003eNodeVM\u003c/code\u003e calls \u003ccode\u003ecrypto.setEngine(pathToBundledLibrary)\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003evm2 forwards the call to the host-realm \u003ccode\u003ecrypto.setEngine\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe host process loads the attacker's dynamic library via the operating system's native loader.\u003c/li\u003e\n\u003cli\u003eThe library's constructor executes arbitrary native code within the host process, achieving full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability allows for a complete sandbox escape, granting the attacker the operating-system identity and permissions of the host Node.js process. Potential impact includes unauthorized access to environment variables, application secrets, credentials, and internal data. Attackers can modify application code, establish persistence, access internal network services, steal data from other tenants sharing the same process, or perform any action permitted to the host user account.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading all instances of the affected vm2 package.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade vm2 to a version beyond 3.11.6 immediately, as there are no configuration-based mitigations that safely allow the \u003ccode\u003ecrypto\u003c/code\u003e builtin while preventing this attack vector.\u003c/li\u003e\n\u003cli\u003eAudit all applications utilizing \u003ccode\u003evm2\u003c/code\u003e for \u003ccode\u003eNodeVM\u003c/code\u003e configurations that grant access to the \u003ccode\u003ecrypto\u003c/code\u003e builtin, specifically in multi-tenant or untrusted plugin scenarios.\u003c/li\u003e\n\u003cli\u003eImplement process-level sandboxing (e.g., containerization, gVisor, or restricted service accounts) to limit the potential impact of native code execution if an application remains vulnerable.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:20:24Z","date_published":"2026-10-01T20:20:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vm2-crypto-rce/","summary":"The vm2 sandbox library (v3.11.3-3.11.6) allows attackers to bypass restrictions and execute arbitrary native code in the host process by calling crypto.setEngine() with a path to a malicious dynamic library.","title":"Arbitrary Native Code Execution in vm2 via crypto.setEngine","url":"https://feed.craftedsignal.io/briefs/2026-10-vm2-crypto-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:openjs_foundation:vm2:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}