CVE-2026-92939
Summary vm2 3.11.6 exposes the host `crypto` module to a `NodeVM` when that single builtin is allowed. The module is presented through a read-only bridge, but its functions still execute with host-process authority. `crypto.setEngine()` accepts a filesystem path and asks OpenSSL to dynamically load the referenced native library. An attacker whose untrusted plugin package contains a native library can therefore load that library into the host process by calling `crypto.setEngine()` from sandboxed JavaScript. The native library's constructor executes before OpenSSL finishes validating whether the file is a usable engine. Consequently, even the expected `ERR_CRYPTO_ENGINE_UNKNOWN` exception occurs only after arbitrary native code has already run. The exploit requires only the `crypto` builtin. It does not require `fs`, `process`, `module`, `child_process`, `worker_threads`, `vm`, `inspector`, unrestricted builtins, or vm2 nesting. ### Details The vulnerable boundary is the generic builtin loader. Builtins that are not specially wrapped or classified as dangerous are imported in the host realm and exposed through a recursive read-only proxy: ```js builtins.set(key, special ? special : vm => vm.readonly(hostRequire(key))); ``` Read-only prevents sandbox code from assigning properties on the module object. It does not reduce the authority of callable exports. Calls are forwarded to the original host function with bridge values converted back to host values. The `crypto` module includes this callable export: ```js crypto.setEngine(enginePath) ``` When `enginePath` names a dynamic library, OpenSSL loads that file into the current process. Operating-system dynamic loaders execute library constructors as part of loading. Engine-symbol validation happens afterward. A file does not have to become a functional cryptographic engine for its constructor to execute. The resulting exploit flow is: ```text attacker supplies an untrusted plugin package containing a native l
Properties
- severity
- critical
- summary
- vm2 crypto builtin loads attacker native code through setEngine
- cvss_score
- 9.9
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T15:28:36Z
- source_url
- https://github.com/advisories/GHSA-46pr-c5wc-xffx
- ghsa_updated
- 2026-10-01T15:28:37Z
- ghsa_id
- GHSA-46pr-c5wc-xffx
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-92939
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- false
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph