Description
vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the underlying host object, so sandbox code can register a listener for the agent's 'free' event. When an unrelated host HTTPS request releases a pooled connection, the listener receives the live host request options and the host TLSSocket, allowing sandboxed code to read the host's Authorization header and private destination host/port, attach a data listener to the released socket and read subsequent host response bodies in plaintext, and issue attacker-chosen authenticated requests using the stolen credentials. The issue is fixed in 3.11.7.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Credential Exposure
Action: Immediate Patch
AI Analysis

Impact

vm2 versions 3.11.3 through 3.11.6 allow sandboxed code to access the host process's real https.globalAgent when the sandbox is configured to permit require('https'). The built‑in loader wraps host modules in a read‑only proxy, but forwarded method calls such as Agent.prototype.on() expose the underlying agent. Sandbox code can therefore register listeners for the agent’s 'free' event, recover the live request options and TLSSocket when a host HTTPS request releases a pooled connection, read the host’s Authorization header, destination host/port, and the plaintext response body, and issue authenticated requests using the stolen credentials.

Affected Systems

The vulnerability affects the patriksimek:vm2 library, specifically releases 3.11.3 through 3.11.6. The fix is included in 3.11.7.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker can supply malicious code to a NodeVM instance that has require('https') enabled, which could happen if user code is trusted or misconfigured. Attackers can collect credentials and intercept network traffic, leading to privilege escalation and data theft.

Generated by OpenCVE AI on September 17, 2026 at 23:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later, which removes the globalAgent exposure.
  • If immediate upgrade is not possible, disable or remove the ability for the NodeVM to load the 'https' module by setting allowRequire to false or restricting the require whitelist to prevent sandbox from accessing it.
  • Audit any sandbox code that uses require('https') to ensure it does not interact with the host’s globalAgent, and monitor logs for unauthorized HTTPS traffic or tampered request headers.

Generated by OpenCVE AI on September 17, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h85j-hv3c-qfgq vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
History

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the underlying host object, so sandbox code can register a listener for the agent's 'free' event. When an unrelated host HTTPS request releases a pooled connection, the listener receives the live host request options and the host TLSSocket, allowing sandboxed code to read the host's Authorization header and private destination host/port, attach a data listener to the released socket and read subsequent host response bodies in plaintext, and issue attacker-chosen authenticated requests using the stolen credentials. The issue is fixed in 3.11.7.
Title vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent
Weaknesses CWE-668
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:20:52.899Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92940

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:55.136Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:59.143

Modified: 2026-09-17T20:18:59.213

Link: CVE-2026-92940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere