Detect CVE-2026-92941: vm2 NodeVM Host TLS Trust Store Replacement in Splunk
Detects exploitation and presence of CVE-2026-92941, a CVSS 10.0 improper permission assignment (CWE-732) flaw in the vm2 npm sandbox library versions 3.11.3 through 3.11.6. Sandboxed (NodeVM) code can reach host-process internals and replace the Node.js TLS trust store (NODE_EXTRA_CA_CERTS / tls.rootCertificates / secureContext), causing the host to trust attacker-controlled CAs. This enables silent man-in-the-middle of all outbound TLS from the host process. Detection focuses on inventorying affected vm2 versions in deployed Node.js applications and spotting runtime indicators: unexpected modification of CA trust files, anomalous additions of custom CA certificates by Node processes, and sandbox escape telemetry (child process spawns, outbound connections to unexpected endpoints) from processes that load vm2.
MITRE ATT&CK
SPL Detection Query
index=* (sourcetype="linux_secure" OR sourcetype="Syslog" OR sourcetype="WinEventLog:Microsoft-Windows-Sysmon/Operational")
(process_name=node OR process_name=node.exe OR Image="*node*")
(file_path="*/etc/ssl/certs*" OR file_path="*ca-certificates*" OR file_path="*cacert.pem*" OR CommandLine="*NODE_EXTRA_CA_CERTS*" OR CommandLine="*tls.rootCertificates*" OR CommandLine="*child_process*")
| stats count min(_time) as firstTime max(_time) as lastTime values(file_path) as files values(CommandLine) as cmds by host process_name user
| convert ctime(firstTime) ctime(lastTime)
| where count > 0
| sort - lastTime Identifies Node.js processes touching CA trust files or invoking TLS-trust/child_process APIs indicative of vm2 escape and trust-store replacement.
Data Sources
Required Sourcetypes
False Positives & Tuning
- Scheduled update-ca-certificates / apt runs modifying the trust store
- Container image builds installing internal corporate CAs
- Node apps configured for TLS inspection proxies via NODE_EXTRA_CA_CERTS
Other platforms for CVE-2026-92941
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Inventory affected vm2 version
Expected signal: Package install telemetry and a package.json reporting version 3.11.6 (within affected range).
- Test 2Simulate Node CA trust store modification
Expected signal: DeviceFileEvents/Sysmon FileCreate with InitiatingProcess=node writing a ca-certificates file.
- Test 3Simulate NODE_EXTRA_CA_CERTS injection and child spawn
Expected signal: Process creation of node with NODE_EXTRA_CA_CERTS in environment/command line and a child process (sh/id) spawn.
References (6)
- https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm
- https://nvd.nist.gov/vuln/detail/CVE-2026-92941
- https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483daa
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://www.vulncheck.com/advisories/vm2-3.11.3-before-3.11.7-tls-trust-store-manipulation
- https://github.com/advisories/GHSA-98xx-8mx4-x7cm
Response Playbook
Triage
- Confirm the affected host runs a Node.js application that bundles vm2; inventory the installed version via package-lock.json / node_modules/vm2/package.json and flag any version >= 3.11.3 and <= 3.11.6.
- Determine whether the vm2 NodeVM/VM is used to execute untrusted or externally-supplied code; if yes, treat the host as high-risk for sandbox escape.
- Inspect CA trust stores (/etc/ssl/certs, system keychain, and the value of NODE_EXTRA_CA_CERTS) for unexpected or recently-added certificates and compare against a known-good baseline.
- Review process and file telemetry from the alerting window for Node processes modifying trust files or spawning child processes.
Containment
- Upgrade vm2 to 3.11.7 or later across all affected deployments; if immediate upgrade is impossible, isolate or disable the service executing untrusted code in vm2.
- Remove any attacker-added CA certificates from the host trust store and unset/validate NODE_EXTRA_CA_CERTS, then restart the Node process to reload a clean secureContext.
- Network-isolate the affected host and rotate credentials/secrets that may have been intercepted via MITM of outbound TLS.
Evidence Collection
- Preserve node_modules/vm2/package.json, package-lock.json, and the running process command line and environment (including NODE_EXTRA_CA_CERTS).
- Capture the current CA trust store contents, file timestamps, and any modified cert bundles for forensic comparison.
- Collect process, file, and network telemetry (EDR/Sysmon/auditd) for the Node process covering the suspected exploitation window.
Escalation Criteria
- !Escalate to IR if attacker-controlled CA certificates are found installed in the host trust store or if NODE_EXTRA_CA_CERTS points to an untrusted file.
- !Escalate if the vm2 sandbox is confirmed to execute externally-supplied code AND outbound TLS traffic shows evidence of interception or redirection to unexpected endpoints.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
Modified CA bundle files (/etc/ssl/certs/ca-certificates.crt, cacert.pem) with recent mtimes - >
Value and target file of NODE_EXTRA_CA_CERTS in the Node process environment - >
node_modules/vm2/package.json showing an affected version (3.11.3–3.11.6)
Tuning Guidance
Baseline legitimate trust-store modifications from package managers (update-ca-certificates, apt) and corporate TLS-inspection CA deployment, then exclude those parent processes and scheduled jobs. Focus alerting on CA-file modifications whose initiating process is a Node application (not a package manager) and that coincide with child_process spawns or vm2 usage. Where possible, enrich with a vm2 version inventory so alerts prioritize hosts running 3.11.3–3.11.6.
Hunting Queries
Hunts for Node.js processes referencing vm2 or the external CA cert environment variable, indicating potential exposure or exploitation.
DeviceProcessEvents | where FileName in~ ("node","node.exe") | where ProcessCommandLine has_any ("vm2","NodeVM","NODE_EXTRA_CA_CERTS") | project Timestamp, DeviceName, ProcessCommandLine, AccountName index=* (process_name=node OR process_name=node.exe) (CommandLine="*vm2*" OR CommandLine="*NODE_EXTRA_CA_CERTS*") | stats count by host, user, CommandLine Atomic Red Team Tests
Detect a vulnerable vm2 version installed in a Node project to validate inventory-based detection.
Command
mkdir -p /tmp/vm2lab && cd /tmp/vm2lab && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && cat node_modules/vm2/package.json | grep '"version"' Cleanup
rm -rf /tmp/vm2lab Expected Telemetry
Package install telemetry and a package.json reporting version 3.11.6 (within affected range).
Expected Detection
Inventory/vulnerability scan flags vm2 3.11.6 as affected by CVE-2026-92941.
Have a Node process write to a CA trust file path to exercise file-modification detection logic.
Command
node -e "require('fs').appendFileSync('/tmp/ca-certificates.crt','-----BEGIN CERTIFICATE-----\nLABTESTCERT\n-----END CERTIFICATE-----\n')" Cleanup
rm -f /tmp/ca-certificates.crt Expected Telemetry
DeviceFileEvents/Sysmon FileCreate with InitiatingProcess=node writing a ca-certificates file.
Expected Detection
KQL/EQL rule matches a Node process modifying a CA trust bundle file.
Launch Node with NODE_EXTRA_CA_CERTS set and spawn a child process to mimic sandbox-escape indicators.
Command
NODE_EXTRA_CA_CERTS=/tmp/evil-ca.pem node -e "require('child_process').execSync('id')" Cleanup
unset NODE_EXTRA_CA_CERTS; rm -f /tmp/evil-ca.pem Expected Telemetry
Process creation of node with NODE_EXTRA_CA_CERTS in environment/command line and a child process (sh/id) spawn.
Expected Detection
Process-based rules match Node invoking child_process with NODE_EXTRA_CA_CERTS set.