Improper access control in vm2 - CVE-2026-93604
Published: September 4, 2026 / Updated: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to alter host process cryptographic configuration and cause a denial of service.
The vulnerability exists due to improper access control in the NodeVM crypto sanitizer when executing untrusted JavaScript in a NodeVM with the crypto builtin allowlisted. A remote attacker can call crypto.setFips to alter host process cryptographic configuration and cause a denial of service.
Exploitation depends on a Node.js/OpenSSL build where crypto.setFips is functional.