<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:openjs_foundation:vm2:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aopenjs_foundationvm2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:20:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aopenjs_foundationvm2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Native Code Execution in vm2 via crypto.setEngine</title><link>https://feed.craftedsignal.io/briefs/2026-10-vm2-crypto-rce/</link><pubDate>Thu, 01 Oct 2026 20:20:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-vm2-crypto-rce/</guid><description>The vm2 sandbox library (v3.11.3-3.11.6) allows attackers to bypass restrictions and execute arbitrary native code in the host process by calling crypto.setEngine() with a path to a malicious dynamic library.</description><content:encoded><![CDATA[<p>The vm2 library, specifically versions 3.11.3 through 3.11.6, contains a critical vulnerability (CVE-2026-92939) that permits sandbox escape and arbitrary native code execution. The vulnerability arises from how vm2 exposes Node.js built-in modules to the sandboxed environment. While vm2 uses a read-only proxy to prevent modification of module properties, it does not restrict the authority of callable exports.</p>
<p>The <code>crypto.setEngine()</code> function is exposed to the sandbox when <code>crypto</code> is an allowed builtin. This function accepts a filesystem path and instructs OpenSSL to load the referenced dynamic library as a cryptographic engine. Crucially, the operating system's dynamic loader executes the library's constructor logic before OpenSSL performs any validation of the library's validity as a cryptographic engine. An attacker providing a malicious package can place a dynamic library on disk and trigger its execution from the sandbox, gaining the privileges of the host process regardless of other sandboxing restrictions.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious package containing a compiled native dynamic library (e.g., .so or .dylib).</li>
<li>Attacker provides the package to an application that processes untrusted plugins (e.g., code runner, automation platform).</li>
<li>The application saves the package contents to the local filesystem.</li>
<li>The application initializes a <code>NodeVM</code> instance, granting access to the <code>crypto</code> builtin but restricting other modules.</li>
<li>The attacker's JavaScript code within the <code>NodeVM</code> calls <code>crypto.setEngine(pathToBundledLibrary)</code>.</li>
<li>vm2 forwards the call to the host-realm <code>crypto.setEngine</code> function.</li>
<li>The host process loads the attacker's dynamic library via the operating system's native loader.</li>
<li>The library's constructor executes arbitrary native code within the host process, achieving full system compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>This vulnerability allows for a complete sandbox escape, granting the attacker the operating-system identity and permissions of the host Node.js process. Potential impact includes unauthorized access to environment variables, application secrets, credentials, and internal data. Attackers can modify application code, establish persistence, access internal network services, steal data from other tenants sharing the same process, or perform any action permitted to the host user account.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize upgrading all instances of the affected vm2 package.</p>
<ul>
<li>Upgrade vm2 to a version beyond 3.11.6 immediately, as there are no configuration-based mitigations that safely allow the <code>crypto</code> builtin while preventing this attack vector.</li>
<li>Audit all applications utilizing <code>vm2</code> for <code>NodeVM</code> configurations that grant access to the <code>crypto</code> builtin, specifically in multi-tenant or untrusted plugin scenarios.</li>
<li>Implement process-level sandboxing (e.g., containerization, gVisor, or restricted service accounts) to limit the potential impact of native code execution if an application remains vulnerable.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>sandbox-escape</category><category>remote-code-execution</category><category>nodejs</category><category>supply-chain</category></item></channel></rss>