CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store
A critical flaw (CVSS 10.0) in vm2 versions 3.11.3–3.11.6 lets code inside a NodeVM sandbox overwrite the host process's default root CA store, forcing all outbound TLS/HTTPS clients to trust attacker-signed certificates. It is fixed in vm2 3.11.7.
- CVSS 10.0: sandboxed code can replace the process-wide Node.js root CAs
- Affects vm2 3.11.3–3.11.6; fixed in 3.11.7
- Enables transparent MitM of all outbound host HTTPS connections
- PoC exists; remove tls and url from allowed builtins as mitigation
Read next
Security