Threats·Cloud & SaaSBreakingvm2 NodeVM Sandbox Escape via crypto.setEngine Enables Arbitrary Host Native Code Execution (CVE-2026-92939)A critical sandbox escape in vm2 allows untrusted NodeVM scripts to invoke OpenSSL engine loading via crypto.setEngine, executing arbitrary native code on the host.CST Newsroom1 Oct 20269 min read