Impact
vm2 versions 3.11.3 through 3.11.6 allow sandboxed code to access the host process's real https.globalAgent when the sandbox is configured to permit require('https'). The built‑in loader wraps host modules in a read‑only proxy, but forwarded method calls such as Agent.prototype.on() expose the underlying agent. Sandbox code can therefore register listeners for the agent’s 'free' event, recover the live request options and TLSSocket when a host HTTPS request releases a pooled connection, read the host’s Authorization header, destination host/port, and the plaintext response body, and issue authenticated requests using the stolen credentials.
Affected Systems
The vulnerability affects the patriksimek:vm2 library, specifically releases 3.11.3 through 3.11.6. The fix is included in 3.11.7.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker can supply malicious code to a NodeVM instance that has require('https') enabled, which could happen if user code is trusted or misconfigured. Attackers can collect credentials and intercept network traffic, leading to privilege escalation and data theft.
OpenCVE Enrichment
Github GHSA