CVE-2026-92941

CVE-2026-92941: vm2 NodeVM Host TLS Trust Store Replacement

Detects exploitation and presence of CVE-2026-92941, a CVSS 10.0 improper permission assignment (CWE-732) flaw in the vm2 npm sandbox library versions 3.11.3 through 3.11.6. Sandboxed (NodeVM) code can reach host-process internals and replace the Node.js TLS trust store (NODE_EXTRA_CA_CERTS / tls.rootCertificates / secureContext), causing the host to trust attacker-controlled CAs. This enables silent man-in-the-middle of all outbound TLS from the host process. Detection focuses on inventorying affected vm2 versions in deployed Node.js applications and spotting runtime indicators: unexpected modification of CA trust files, anomalous additions of custom CA certificates by Node processes, and sandbox escape telemetry (child process spawns, outbound connections to unexpected endpoints) from processes that load vm2.

Vulnerability Intelligence

Public PoC

What is CVE-2026-92941 CVE-2026-92941: vm2 NodeVM Host TLS Trust Store Replacement?

CVE-2026-92941: vm2 NodeVM Host TLS Trust Store Replacement (CVE-2026-92941) maps to the Defense Evasion and Privilege Escalation and Credential Access tactics — the adversary is trying to avoid being detected in MITRE ATT&CK.

This page provides production-ready detection logic for CVE-2026-92941: vm2 NodeVM Host TLS Trust Store Replacement, covering the data sources and telemetry it touches: Microsoft Defender for Endpoint. The queries below are rated critical severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.

MITRE ATT&CK

Tactic
Defense Evasion Privilege Escalation Credential Access
Microsoft Sentinel / Defender
kusto
// CVE-2026-92941 — vm2 TLS trust store manipulation / sandbox escape indicators
let caTrustFiles = dynamic(["ca-certificates.crt","cacert.pem","ca-bundle.crt","NODE_EXTRA_CA_CERTS"]);
union isfuzzy=true
(
DeviceFileEvents
| where Timestamp > ago(24h)
| where InitiatingProcessFileName in~ ("node","node.exe")
| where ActionType in ("FileCreated","FileModified")
| where FileName has_any (caTrustFiles) or FolderPath has_any ("/etc/ssl/certs","/usr/local/share/ca-certificates","ca-trust")
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, InitiatingProcessCommandLine, InitiatingProcessAccountName
),
(
DeviceProcessEvents
| where Timestamp > ago(24h)
| where InitiatingProcessFileName in~ ("node","node.exe")
| where ProcessCommandLine has_any ("NODE_EXTRA_CA_CERTS","tls.rootCertificates","setGlobalDispatcher","child_process","spawn")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, AccountName
)
| order by Timestamp desc

Surfaces Node.js processes modifying CA trust stores or spawning children with TLS-trust / child_process indicators consistent with vm2 sandbox escape and trust-store replacement.

critical severity medium confidence

Data Sources

Microsoft Defender for Endpoint

Required Tables

DeviceFileEvents DeviceProcessEvents

False Positives

  • Legitimate package managers (apt, update-ca-certificates) updating the system trust store on a schedule
  • CI/CD build agents that install custom internal CA certificates during image bake
  • Node applications that legitimately set NODE_EXTRA_CA_CERTS for corporate TLS inspection proxies

Sigma rule & cross-platform mapping

The detection logic for CVE-2026-92941: vm2 NodeVM Host TLS Trust Store Replacement (CVE-2026-92941) above is provided in a vendor-neutral form so you can deploy it on any SIEM. The same logic is shipped here as native KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the following logsource:

logsource:
  category: process_creation
  product: windows

Browse the community-maintained Sigma rules for this technique:


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Inventory affected vm2 version

    Expected signal: Package install telemetry and a package.json reporting version 3.11.6 (within affected range).

  2. Test 2Simulate Node CA trust store modification

    Expected signal: DeviceFileEvents/Sysmon FileCreate with InitiatingProcess=node writing a ca-certificates file.

  3. Test 3Simulate NODE_EXTRA_CA_CERTS injection and child spawn

    Expected signal: Process creation of node with NODE_EXTRA_CA_CERTS in environment/command line and a child process (sh/id) spawn.


Response Playbook

Triage

  1. Confirm the affected host runs a Node.js application that bundles vm2; inventory the installed version via package-lock.json / node_modules/vm2/package.json and flag any version >= 3.11.3 and <= 3.11.6.
  2. Determine whether the vm2 NodeVM/VM is used to execute untrusted or externally-supplied code; if yes, treat the host as high-risk for sandbox escape.
  3. Inspect CA trust stores (/etc/ssl/certs, system keychain, and the value of NODE_EXTRA_CA_CERTS) for unexpected or recently-added certificates and compare against a known-good baseline.
  4. Review process and file telemetry from the alerting window for Node processes modifying trust files or spawning child processes.

Containment

  1. Upgrade vm2 to 3.11.7 or later across all affected deployments; if immediate upgrade is impossible, isolate or disable the service executing untrusted code in vm2.
  2. Remove any attacker-added CA certificates from the host trust store and unset/validate NODE_EXTRA_CA_CERTS, then restart the Node process to reload a clean secureContext.
  3. Network-isolate the affected host and rotate credentials/secrets that may have been intercepted via MITM of outbound TLS.

Evidence Collection

  1. Preserve node_modules/vm2/package.json, package-lock.json, and the running process command line and environment (including NODE_EXTRA_CA_CERTS).
  2. Capture the current CA trust store contents, file timestamps, and any modified cert bundles for forensic comparison.
  3. Collect process, file, and network telemetry (EDR/Sysmon/auditd) for the Node process covering the suspected exploitation window.

Escalation Criteria

  • ! Escalate to IR if attacker-controlled CA certificates are found installed in the host trust store or if NODE_EXTRA_CA_CERTS points to an untrusted file.
  • ! Escalate if the vm2 sandbox is confirmed to execute externally-supplied code AND outbound TLS traffic shows evidence of interception or redirection to unexpected endpoints.

Investigation Guide

Forensic Artifacts

  • > Modified CA bundle files (/etc/ssl/certs/ca-certificates.crt, cacert.pem) with recent mtimes
  • > Value and target file of NODE_EXTRA_CA_CERTS in the Node process environment
  • > node_modules/vm2/package.json showing an affected version (3.11.3–3.11.6)

Tuning Guidance

Baseline legitimate trust-store modifications from package managers (update-ca-certificates, apt) and corporate TLS-inspection CA deployment, then exclude those parent processes and scheduled jobs. Focus alerting on CA-file modifications whose initiating process is a Node application (not a package manager) and that coincide with child_process spawns or vm2 usage. Where possible, enrich with a vm2 version inventory so alerts prioritize hosts running 3.11.3–3.11.6.


Hunting Queries

Hunts for Node.js processes referencing vm2 or the external CA cert environment variable, indicating potential exposure or exploitation.

Hunting — KQL
kql
DeviceProcessEvents | where FileName in~ ("node","node.exe") | where ProcessCommandLine has_any ("vm2","NodeVM","NODE_EXTRA_CA_CERTS") | project Timestamp, DeviceName, ProcessCommandLine, AccountName
Hunting — SPL
spl
index=* (process_name=node OR process_name=node.exe) (CommandLine="*vm2*" OR CommandLine="*NODE_EXTRA_CA_CERTS*") | stats count by host, user, CommandLine

Atomic Red Team Tests

Test 1 Inventory affected vm2 version
linux

Detect a vulnerable vm2 version installed in a Node project to validate inventory-based detection.

Command

bash
mkdir -p /tmp/vm2lab && cd /tmp/vm2lab && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && cat node_modules/vm2/package.json | grep '"version"'

Cleanup

bash
rm -rf /tmp/vm2lab

Expected Telemetry

Package install telemetry and a package.json reporting version 3.11.6 (within affected range).

Expected Detection

Inventory/vulnerability scan flags vm2 3.11.6 as affected by CVE-2026-92941.

Test 2 Simulate Node CA trust store modification
linux

Have a Node process write to a CA trust file path to exercise file-modification detection logic.

Command

bash
node -e "require('fs').appendFileSync('/tmp/ca-certificates.crt','-----BEGIN CERTIFICATE-----\nLABTESTCERT\n-----END CERTIFICATE-----\n')"

Cleanup

bash
rm -f /tmp/ca-certificates.crt

Expected Telemetry

DeviceFileEvents/Sysmon FileCreate with InitiatingProcess=node writing a ca-certificates file.

Expected Detection

KQL/EQL rule matches a Node process modifying a CA trust bundle file.

Test 3 Simulate NODE_EXTRA_CA_CERTS injection and child spawn
linux

Launch Node with NODE_EXTRA_CA_CERTS set and spawn a child process to mimic sandbox-escape indicators.

Command

bash
NODE_EXTRA_CA_CERTS=/tmp/evil-ca.pem node -e "require('child_process').execSync('id')"

Cleanup

bash
unset NODE_EXTRA_CA_CERTS; rm -f /tmp/evil-ca.pem

Expected Telemetry

Process creation of node with NODE_EXTRA_CA_CERTS in environment/command line and a child process (sh/id) spawn.

Expected Detection

Process-based rules match Node invoking child_process with NODE_EXTRA_CA_CERTS set.

Related Detections