chiprook
← Security
SecurityOctober 2, 2026, 18:31

CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store

A critical flaw (CVSS 10.0) in vm2 versions 3.11.3–3.11.6 lets code inside a NodeVM sandbox overwrite the host process's default root CA store, forcing all outbound TLS/HTTPS clients to trust attacker-signed certificates. It is fixed in vm2 3.11.7.

CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store
#Vm2#Node.js
Read next
Security

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets

Security

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass

Security

Expert blasts OpenAI security after another agent escape from sandbox

Security

Researchers escape OpenAI Codex sandbox to run commands on host