criticalCVSS 9.9Vulnerability

CVE-2026-92939

Summary vm2 3.11.6 exposes the host `crypto` module to a `NodeVM` when that single builtin is allowed. The module is presented through a read-only bridge, but its functions still execute with host-process authority. `crypto.setEngine()` accepts a filesystem path and asks OpenSSL to dynamically load the referenced native library. An attacker whose untrusted plugin package contains a native library can therefore load that library into the host process by calling `crypto.setEngine()` from sandboxed JavaScript. The native library's constructor executes before OpenSSL finishes validating whether the file is a usable engine. Consequently, even the expected `ERR_CRYPTO_ENGINE_UNKNOWN` exception occurs only after arbitrary native code has already run. The exploit requires only the `crypto` builtin. It does not require `fs`, `process`, `module`, `child_process`, `worker_threads`, `vm`, `inspector`, unrestricted builtins, or vm2 nesting. ### Details The vulnerable boundary is the generic builtin loader. Builtins that are not specially wrapped or classified as dangerous are imported in the host realm and exposed through a recursive read-only proxy: ```js builtins.set(key, special ? special : vm => vm.readonly(hostRequire(key))); ``` Read-only prevents sandbox code from assigning properties on the module object. It does not reduce the authority of callable exports. Calls are forwarded to the original host function with bridge values converted back to host values. The `crypto` module includes this callable export: ```js crypto.setEngine(enginePath) ``` When `enginePath` names a dynamic library, OpenSSL loads that file into the current process. Operating-system dynamic loaders execute library constructors as part of loading. Engine-symbol validation happens afterward. A file does not have to become a functional cryptographic engine for its constructor to execute. The resulting exploit flow is: ```text attacker supplies an untrusted plugin package containing a native l

Properties

severity
critical
summary
vm2 crypto builtin loads attacker native code through setEngine
cvss_score
9.9
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:28:36Z
source_url
https://github.com/advisories/GHSA-46pr-c5wc-xffx
ghsa_updated
2026-10-01T15:28:37Z
ghsa_id
GHSA-46pr-c5wc-xffx
last_source
GitHub Advisory Database
cve_id
CVE-2026-92939
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (4)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Process Control

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92939 (CVSS 9.9) — Ninja Signal Threat Intelligence | Ninja Signal