criticalCVSS 10Vulnerability

CVE-2026-92941

Summary vm2 3.11.6 exposes the host `tls` module to a `NodeVM` when that builtin is explicitly allowed. Although the module object is wrapped as read-only, its functions still execute against process-wide host state. On Node.js versions that provide `tls.setDefaultCACertificates()`, sandbox code can replace the certificate authorities trusted by subsequent host-realm TLS clients. The exploit needs only the narrowly allowed `tls` and `url` builtins. It does not require `fs`, `process`, `module`, `child_process`, an external package, or a general `'*'` builtin grant. A host HTTPS request rejected an attacker certificate before sandbox execution, then accepted the same certificate and returned an application marker after the sandbox replaced the default CA list. This crosses the intended sandbox boundary. An attacker can make host HTTPS clients trust an attacker-controlled CA, enabling credential theft and response tampering when the attacker can influence a subsequent destination or network path. Replacing the list also removes the normal trust roots, disrupting unrelated host TLS traffic. ### Details The vulnerable boundary is the default builtin loader in `lib/builtin.js`. Builtins that are not classified as dangerous are exposed through a recursive read-only bridge: ```js builtins.set(key, special ? special : vm => vm.readonly(hostRequire(key))); ``` The read-only wrapper prevents ordinary property assignment through the sandbox proxy. It does not make calls such as `tls.setDefaultCACertificates()` sandbox-local. That function changes the default CA list for the current Node.js thread and affects subsequent TLS connections that do not provide their own `ca` option. The dangerous-builtin list now rejects `dns` because `dns.setServers()` mutates process-wide host networking state. It does not reject `tls`, even though current Node.js exposes an equivalent process-wide trust mutation through it. A direct call with a normal sandbox array is not necessary. The

Properties

severity
critical
summary
vm2 NodeVM can replace the host process TLS trust store
cvss_score
10
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:27:28Z
source_url
https://github.com/advisories/GHSA-98xx-8mx4-x7cm
ghsa_updated
2026-10-01T15:27:29Z
ghsa_id
GHSA-98xx-8mx4-x7cm
last_source
GitHub Advisory Database
cve_id
CVE-2026-92941
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (4)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Incorrect Permission Assignment for Critical Resource

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92941 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal