Description
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: TLS Trust Store Manipulation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in vm2 allows code running in a sandboxed environment to forcibly manipulate the host application's TLS trust store. By calling tls.setDefaultCACertificates() from the sandbox, attackers can replace the global list of trusted certificate authorities with ones of their choosing. This enables subsequent HTTPS requests from the host process to accept attacker‑controlled certificates, creating a path for man‑in‑the‑middle attacks, data exfiltration, and credential compromise. The weakness arises from incorrect authorization (CWE-732) permitting unrestricted access to the node tls module from restricted code.

Affected Systems

Vulnerable versions are vm2 3.11.3 through 3.11.6, distributed by patriksimek. The issue manifests when the module exposes the host's tls API to sandboxed code that has access to the tls and url built‑ins. The fix is implemented in version 3.11.7, which removes the unprotected exposure of the tls module.

Risk and Exploitability

The CVSS score is 10.0, indicating an exploitable vulnerability with full confidentiality, integrity, and availability impact. Although the EPSS score is not available, the high CVSS combined with the ease of manipulation via NodeVM and the lack of KEV listing suggests that a motivated attacker could exploit it. The attacker must be able to inject JavaScript into the vm2 sandbox with access to the tls and url modules; once this is achieved, the exploit can replace the system certificates and hijack traffic for any HTTPS client used by the host.

Generated by OpenCVE AI on September 17, 2026 at 23:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later, which removes the TLS module exposure.
  • If an upgrade cannot be performed immediately, configure NodeVM to disable the tls and url built‑ins, limiting sandbox access to no TLS manipulation.
  • Implement certificate pinning or monitor outbound TLS connections and reject connections that use certificates not signed by known authorities.

Generated by OpenCVE AI on September 17, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-98xx-8mx4-x7cm vm2 NodeVM can replace the host process TLS trust store
History

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.
Title vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:48:59.103Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92941

cve-icon Vulnrichment

Updated: 2026-09-17T15:48:51.299Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:59.310

Modified: 2026-09-17T16:18:34.520

Link: CVE-2026-92941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource