PT-2026-94313 · Npm · Vm2

·

CVE-2026-92941

·

Published

2026-08-25

·

Updated

2026-09-20

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions vm2 versions 3.11.3 through 3.11.6
Description The host tls module is exposed to NodeVM sandbox code, which allows attackers to call the setDefaultCACertificates() function and replace process-wide certificate authorities. By utilizing allowed tls and url builtins, attackers can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store. This enables subsequent host HTTPS clients to accept certificates controlled by the attacker, leading to a full sandbox escape.
Recommendations Update vm2 to version 3.11.7 or later.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14936
CVE-2026-92941
GHSA-98XX-8MX4-X7CM

Affected Products

Vm2