Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsvm2 3.11.3 through 3.11.6 are affected by CVE-2026-92941; vm2 3.11.7 fixes it. The described exploit requires a NodeVM that allows both Node.js builtins tls and url, plus a runtime that provides tls.setDefaultCACertificates(). It lets sandboxed code change the host process’s default certificate authorities for later TLS connections that do not supply their own CA list. Upgrade affected installations and check the NodeVM allowlist.
Which vm2 versions are affected?
The vm2 maintainer identifies versions 3.11.3 through 3.11.6, inclusive, as affected. Version 3.11.7 is patched. GitLab Advisory Database rates CVE-2026-92941 10.0 (Critical) under CVSS v3.1; that is the database’s published severity rating, not a measure of how many deployments are affected or whether exploitation is occurring in the wild.
The described path also depends on configuration and runtime—not just the package version. The NodeVM must explicitly allow both tls and url, and the Node.js runtime must provide tls.setDefaultCACertificates(). The maintainer reports that API in Node.js 22.19.0 and later in the 22.x line, and 24.5.0 and later in the 24.x line. Check the actual deployed runtime rather than assuming the API exists in every Node.js release.
Sources: vm2 maintainer security advisories; vm2 v3.11.7 release notes; GitLab Advisory Database; Node.js TLS API documentation.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What does CVE-2026-92941 let sandboxed code do?
It allows code running inside a qualifying NodeVM to change the default CA list used by the host Node.js thread for subsequent TLS connections that do not provide their own ca option. This crosses the intended sandbox boundary, but the demonstrated proof of concept is not direct arbitrary file access or shell-command execution.
How the trust-store change works
vm2 can expose selected Node.js builtins to NodeVM code through a bridge. In the affected setup, the host allows tls and url. Although the exposed tls object is wrapped read-only, that does not make its function calls sandbox-local: calling tls.setDefaultCACertificates() changes a default used by the host thread.
The reported path uses the allowed url builtin as well. URLSearchParams.getAll() returns an array from the host realm. When that mapped array passes back through the vm2 bridge, it is unwrapped in a form accepted by the native TLS API. The API then installs the supplied CA list for later host-side connections. According to the maintainer, this path does not require allowing fs, process, module, or child_process, installing an external package, or granting wildcard access to builtins.
What the proof of concept demonstrates
The maintainer’s local demonstration creates a temporary CA and a loopback HTTPS server. A host request fails certificate verification before sandbox execution; after sandboxed code changes the default CA list, a subsequent host request succeeds. It makes no external request. This demonstrates that sandboxed code can manipulate a host trust decision; it does not demonstrate credential theft, shell access, or exploitation of an outside server.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
What is the practical security impact?
If an attacker can submit code to a NodeVM with the required configuration and the vulnerable runtime API, they may replace the default CA set used by later host TLS clients. If they can also influence a later destination or its network path—for example through DNS, routing, or a proxy—the host may accept a certificate signed by an attacker, potentially exposing credentials or allowing responses to be altered. Replacing the defaults can also remove normal trust roots and cause unrelated TLS connections to fail.
- Connections that explicitly provide their own
caoption are not affected by the changed defaults, according to the maintainer. - Already cached TLS sessions may remain unchanged.
- The proof of concept does not provide a direct file- or command-execution primitive.
These limits matter when assessing exposure: the issue is a serious host trust-boundary failure, but it should not be described as a generic sandbox-to-shell exploit.
Rank #4
- Tamper Resistant Star Key Set Crafted with premium chrome vanadium steel, and each star tool folds neatly into the handle for quick, easy access.
- Details - The handle is engraved with size for quick identification with drilled tips to allow use.
- Portable - Keys fold compact for easy storage, Drilled tips allow use on tamper resistant security screws.
- Size:Full Size T-6, T-7, T-8, T-9, T-10, T-15 T-20, T-25, T-27 and T-30.
- And with 10 total star sizes able to match nearly all standard tamper resistant security screws on the market.
How do you fix CVE-2026-92941?
- Find the installed vm2 version. Inspect the dependency manifest and lockfile, and check the resolved package in the deployed application. Look for versions 3.11.3–3.11.6.
- Upgrade vm2 to 3.11.7 or later. The vm2 maintainer identifies 3.11.7 as patched. Deploy the updated dependency through your normal build and release process.
- Audit each NodeVM configuration. Review the builtin allowlist and confirm whether both
tlsandurlare exposed. Do not treat read-only wrappers as protection against process-wide state-changing functions. - Verify the deployed runtime and application behavior. Check the actual Node.js version and test the application after upgrading. The v3.11.7 release notes describe a patch release without API changes, but also list observable behavior changes and upgrade notes, including changes involving the CLI and builtin deny tokens.
Removing tls or url from an allowlist can reduce exposure to this specific path if the application does not need them, but the maintainer’s stated fix is upgrading. Do not treat a configuration change as equivalent to the patched package.
Sources: vm2 maintainer security advisories; vm2 v3.11.7 release notes.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

