PT-2026-95383 · Npm · Vm2
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.12.1
Description
When an embedder explicitly allowlists the
crypto builtin for a NodeVM using require.builtin: ['crypto'], the crypto.setFips() function is exposed to untrusted guest code. This occurs because the builtin sanitizer sanitizeCryptoModule() in lib/builtin.js replaces crypto.setEngine() but fails to remove crypto.setFips(). Additionally, the readonly wrapper used to expose the host module does not localize side effects of forwarded host functions. Consequently, guest code can call crypto.setFips() to change the FIPS (Federal Information Processing Standards) mode of the entire host process, allowing the modified mode to be observed by trusted host code and crossing the NodeVM isolation boundary.Recommendations
Update to version 3.12.1.
As a temporary workaround, avoid allowlisting the
crypto builtin in the NodeVM configuration until the update is applied.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2