PT-2026-94312 · Npm · Vm2

·

CVE-2026-92940

·

Published

2026-08-25

·

Updated

2026-09-17

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions vm2 versions 3.11.3 through 3.11.6
Description When a NodeVM is configured to allow require('https'), the host process's https.globalAgent is exposed to sandboxed code. Although the builtin loader uses a read-only proxy for host modules, method calls like Agent.prototype.on() are forwarded to the host object. This allows sandboxed code to register a listener for the free event of the agent. When a host HTTPS request releases a pooled connection, the listener gains access to the host request options and the host TLSSocket. Consequently, sandboxed code can read the Authorization header and private destination host/port, intercept subsequent host response bodies in plaintext, and perform authenticated requests using stolen credentials.
Recommendations Update vm2 to version 3.11.7.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14935
CVE-2026-92940
GHSA-H85J-HV3C-QFGQ

Affected Products

Vm2