criticalCVSS 10Vulnerability

CVE-2026-92940

Summary vm2 3.11.6 exposes the host process's real `https.globalAgent` when a `NodeVM` is explicitly allowed to require `https`. The module is wrapped as read-only, but calls to methods on the shared agent still mutate the host object. Sandbox code can register a `free` listener and receive host request options and the host TLS socket whenever an unrelated host HTTPS request releases a pooled connection. In a contained test, sandbox code allowed only the `https` builtin: - read the host request's bearer token from the agent event; - attached a data listener to the released host TLS socket and read the next host response body in plaintext; - learned the private service host and port; - sent an attacker-chosen authenticated POST using the stolen host token; and - received confirmation that the service accepted the action. The host application never passed its credentials, request, response, socket, or destination into the sandbox. They crossed the boundary solely because vm2 exposes the process-global HTTPS agent instead of a sandbox-local network module instance. ### Details The vulnerable boundary is the default builtin loader in `lib/builtin.js`: ```js builtins.set(key, special ? special : vm => vm.readonly(hostRequire(key))); ``` The wrapper recursively exposes properties of the actual host module. For ordinary constants, a read-only proxy can be sufficient. It is not sufficient for process-global EventEmitter objects whose methods mutate internal state. `https.globalAgent` is the default agent used by host HTTPS requests when the host does not supply a separate `agent`. The agent is shared by the entire Node.js thread. Its `free` event supplies both: - the `TLSSocket` that has just completed a request and is available for reuse; and - the connection/request options used to place that socket in the pool. The following sandbox code registers directly on that host singleton: ```js const https = require('https'); https.globalAgent.on('free', (socket, opt

Properties

severity
critical
summary
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
cvss_score
10
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:38:26Z
source_url
https://github.com/advisories/GHSA-h85j-hv3c-qfgq
ghsa_updated
2026-10-01T15:39:28Z
ghsa_id
GHSA-h85j-hv3c-qfgq
last_source
GitHub Advisory Database
cve_id
CVE-2026-92940
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Exposure of Resource to Wrong Sphere

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92940 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal