← Back to search

CVE-2026-92939

9.9 CRITICALpublic exploit available

Published 2026-09-17 · Updated 2026-09-17

AI risk analysis

Summary
This flaw allows sandboxed JavaScript to escape the NodeVM sandbox by calling the crypto.setEngine() method with a filesystem path to an attacker-supplied native library, leading to arbitrary code execution.
Exploitability
Exploitation is relatively straightforward as it requires only the crypto builtin and no other Node.js features, making it a significant risk.
Blast radius
If exploited, this flaw could lead to full control over the host system, enabling attackers to execute arbitrary code with the privileges of the Node.js process.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to vm2 3.11.7 or later.
rcecryptovmnodejssandbox-escapenative-code-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an untrusted plugin package already written to disk); OpenSSL asks the operating-system dynamic loader to load the file, and the library's constructor executes native code in the host process before engine-symbol validation rejects it. Exploitation requires only the crypto builtin and does not require fs, process, module, child_process, worker_threads, vm, or inspector access, resulting in a sandbox escape and arbitrary native code execution. Fixed in 3.11.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-114

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.