PT-2026-94312 · Npm · Vm2
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.11.3 through 3.11.6
Description
When a NodeVM is configured to allow
require('https'), the host process's https.globalAgent is exposed to sandboxed code. Although the builtin loader uses a read-only proxy for host modules, method calls like Agent.prototype.on() are forwarded to the host object. This allows sandboxed code to register a listener for the free event of the agent. When a host HTTPS request releases a pooled connection, the listener gains access to the host request options and the host TLSSocket. Consequently, sandboxed code can read the Authorization header and private destination host/port, intercept subsequent host response bodies in plaintext, and perform authenticated requests using stolen credentials.Recommendations
Update vm2 to version 3.11.7.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2