External risk intelligence

vm2 Sandbox Escape via Crypto Module

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-92939

This is a vulnerability in a sandboxing library (vm2) used by developers within applications. While it can be present in internet-facing web applications that utilize this sandbox to execute untrusted code, the library itself is a backend development component. Its exposure is dependent on specific application architecture rather than being a default internet-facing service or appliance.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in the vm2 library, a tool used to create secure sandboxes for running untrusted code. The issue allows code within the sandbox to execute commands on the host system with the authority of the host process, potentially leading to unauthorized native code execution. While the library is designed for security, this flaw bypasses its protections when specific functionalities are enabled.

  • Sandbox escape allows host code execution.
  • Critical vulnerability in a widely used security tool.
  • Verify if this library is used in your applications.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by leveraging the Node.js crypto module within the vm2 sandbox. If the crypto module is permitted, an attacker can call `crypto.setEngine()` with a path to a malicious native library. This library will then execute with host-process authority, allowing the attacker to escape the sandbox and run arbitrary native code.

  • Requires access to the crypto builtin.
  • Calls `crypto.setEngine()` with a malicious library.
  • Leads to sandbox escape and code execution.

Live Threat

Current exploitation, exposure, and threat context

When the `crypto` builtin is exposed within a Node.js environment, an attacker could potentially execute arbitrary native code on the host system. This occurs when sandboxed JavaScript code calls the `crypto.setEngine()` function, allowing the loading and execution of a malicious native library.

  • Host process authority and native code.
  • Exploited via exposed `crypto` builtin.
  • Arbitrary native code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 library's vulnerability requires investigation by teams responsible for applications that use it for sandboxing, particularly if they permit the crypto builtin and load untrusted code. The first practical move is to identify all instances of affected vm2 versions, assess their reachability and criticality, and then determine the accountable application owner to plan remediation.

  • Application owners should address this issue.
  • Verify crypto builtin and untrusted code loading.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and what is it used for?

vm2 is a Node.js library that developers use to create a sandboxed environment for executing untrusted JavaScript code. By running code in this isolated container, developers aim to prevent the untrusted script from interacting with or damaging the main host system. It is commonly used in applications that need to process user-provided plugins or dynamic scripts safely.

How does CVE-2026-92939 enable a sandbox escape?

This vulnerability, classified as CWE-114 (Process Control), allows code inside the sandbox to interact improperly with the host's native environment. Because the host's crypto module is incorrectly exposed to the sandbox, an attacker can trigger the loading of an arbitrary native library file. This bypasses the sandbox's security boundaries, granting the attacker the ability to execute native code with the authority of the host process.

Do I need the crypto module to trigger this vulnerability?

Yes. This specific sandbox escape requires that the Node.js crypto built-in module is explicitly allowed within the vm2 configuration. If your implementation of vm2 does not expose the crypto module to the sandboxed code, or if you are not using the library to run untrusted code that could call the crypto API, this particular trigger path is not available.

Is my application at risk if it uses vm2?

Risk depends on how your application uses the library. According to Halo Surface Signal, vm2 is a development component, not an internet-facing appliance. Your exposure depends on your application's architecture: if you use vm2 to execute untrusted code in a way that allows access to the crypto module, the risk is higher, especially if that application is accessible from the network.

What should I do if my software uses affected vm2 versions?

First, locate all instances of vm2 versions 3.11.3 through 3.11.6 in your codebase. Identify which applications explicitly permit the crypto built-in within their sandbox configuration. Once identified, work with the application owners to plan an update to version 3.11.7, which contains the fix for this flaw, or restrict the use of the crypto module within the sandbox.

References