PT-2026-95383 · Npm · Vm2

·

CVE-2026-93604

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.12.1
Description When an embedder explicitly allowlists the crypto builtin for a NodeVM using require.builtin: ['crypto'], the crypto.setFips() function is exposed to untrusted guest code. This occurs because the builtin sanitizer sanitizeCryptoModule() in lib/builtin.js replaces crypto.setEngine() but fails to remove crypto.setFips(). Additionally, the readonly wrapper used to expose the host module does not localize side effects of forwarded host functions. Consequently, guest code can call crypto.setFips() to change the FIPS (Federal Information Processing Standards) mode of the entire host process, allowing the modified mode to be observed by trusted host code and crossing the NodeVM isolation boundary.
Recommendations Update to version 3.12.1. As a temporary workaround, avoid allowlisting the crypto builtin in the NodeVM configuration until the update is applied.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93604
GHSA-X3V6-43HC-82MC

Affected Products

Vm2