CVE-2026-93604 | patriksimek vm2 up to 3.12.0 Builtin Sanitizer lib/builtin.js crypto.setFips isolation
A vulnerability was found in patriksimek vm2 up to 3.12.0 and classified as critical. The impacted element is the function crypto.setFips of the file lib/builtin.js of the component Builtin Sanitizer. The manipulation results in improper isolation or compartmentalization.
This vulnerability is reported as CVE-2026-93604. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More