External risk intelligence

vm2 TLS Trust Store Manipulation Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-92941

The vulnerability affects a sandbox library (vm2) used by developers within Node.js applications. While an application using this library might be internet-facing, the sandbox itself is a component used during application development or execution logic, not a direct public-facing network service, appliance, or gateway.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a critical vulnerability in the vm2 sandbox library that could allow an attacker to tamper with trust certificates. This could lead to applications accepting fraudulent security credentials, potentially impacting secure communications. The main concern is confirming relevance and exposure within your technology environment.

  • Sandbox vulnerability allows certificate tampering.
  • Critical issue impacts secure communication trust.
  • Confirm if your applications use this library.

Attack Path

How an attacker could exploit the issue

An attacker who can execute code within the Node.js `vm2` sandbox could manipulate the process's trusted certificate authorities. This is achieved by leveraging built-in `tls` and `url` modules to bypass sandbox restrictions and modify the system's TLS trust store. Subsequently, any host HTTPS clients within that process could be tricked into accepting connections to servers using attacker-controlled certificates.

  • Attacker must run code in sandbox.
  • Vulnerable `tls` and `url` features are used.
  • Enables accepting fake certificates.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, specially crafted Node.js applications that allow untrusted code to execute within a vm2 sandbox could manipulate the system's TLS certificate authorities. This manipulation may enable subsequent host HTTPS client connections to trust attacker-controlled certificates.

  • System TLS trust store.
  • Execution of sandboxed code.
  • Host HTTPS clients could be compromised.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the vm2 library could allow attackers to manipulate TLS certificate authorities, impacting the trust of HTTPS connections made by Node.js applications. Application owners, platform teams, and security teams should collaborate to identify instances of the affected library, assess their exposure, and coordinate remediation. The initial practical step involves discovering where vm2 is deployed, determining reachability and criticality, and then planning the appropriate response based on risk.

  • Application owners should manage this issue.
  • Verify usage and reachability of vm2.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is vm2 and why is it used?

vm2 is a popular Node.js library designed to provide a secure sandbox for running untrusted code. Developers use it to execute external or dynamic scripts safely by isolating that code from the main application's environment, preventing the script from accessing system resources or sensitive data directly.

What is the security weakness in CVE-2026-92941?

This vulnerability, classified as CWE-732, involves incorrect permission assignment. It occurs because the sandbox incorrectly exposes the host's 'tls' and 'url' modules to the code running inside it. This flaw allows malicious code to break out of its restricted environment and interact with system-wide certificate settings.

How can an attacker trigger this vulnerability?

An attacker must be able to execute arbitrary code inside the vm2 sandbox. Simply interacting with an application is not enough; the attacker needs a way to run their own logic within the sandboxed environment. If the sandbox is correctly configured to block all access to built-in 'tls' or 'url' modules, the specific conditions required to manipulate the trust store will not be met.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that risk is unlikely for direct public-facing services. Because vm2 is a developer-focused library used inside application logic rather than a standalone network service or gateway, the sandbox itself is not directly reachable from the internet. You should focus on applications that specifically allow users to supply or execute custom code within these sandboxes.

How do I start addressing this issue?

Your first step is to perform a software inventory to identify which applications include vm2 versions 3.11.3 through 3.11.6. Once located, evaluate whether these applications execute untrusted or user-supplied code. After identifying these high-risk areas, coordinate with your development teams to update to version 3.11.7 or newer.

References