Npm · Vm2 · CVE-2026-92939
**Name of the Vulnerable Software and Affected Versions**
vm2 versions 3.11.3 through 3.11.6
**Description**
When the crypto builtin is allowed, the host Node.js crypto module is exposed to a NodeVM sandbox. Although the module is presented via a recursive read-only proxy, its callable exports still execute with host-process authority. This allows sandboxed JavaScript to call the `setEngine()` function with a filesystem path to an attacker-supplied native library. OpenSSL then requests the operating-system dynamic loader to load the file, causing the library's constructor to execute native code in the host process before engine-symbol validation rejects it. This leads to a sandbox escape and arbitrary native code execution, requiring only the crypto builtin without needing access to `fs`, `process`, `module`, `child process`, `worker threads`, `vm`, or `inspector`.
**Recommendations**
Update to version 3.11.7.
As a temporary workaround, restrict the use of the crypto builtin in the NodeVM sandbox.