PT-2026-94313 · Npm · Vm2
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.11.3 through 3.11.6
Description
The host tls module is exposed to NodeVM sandbox code, which allows attackers to call the
setDefaultCACertificates() function and replace process-wide certificate authorities. By utilizing allowed tls and url builtins, attackers can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store. This enables subsequent host HTTPS clients to accept certificates controlled by the attacker, leading to a full sandbox escape.Recommendations
Update vm2 to version 3.11.7 or later.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2