CVE-2026-92940: CVE-2026-92940: Host-Realm Credential Exposure and Socket Hijacking via globalAgent in vm2
CVE-2026-92940: Host-Realm Credential Exposure and Socket Hijacking via globalAgent in vm2 Vulnerability ID: CVE-2026-92940 CVSS Score: 10.0 Published: 2026-10-01 A critical vulnerability in the Node.js sandbox libr
CVE-2026-92940: Host-Realm Credential Exposure and Socket Hijacking via globalAgent in vm2
Vulnerability ID: CVE-2026-92940
CVSS Score: 10.0
Published: 2026-10-01
A critical vulnerability in the Node.js sandbox library vm2 allows sandboxed code to retrieve the process-wide http.globalAgent and https.globalAgent singletons. By attaching event listeners to these host-realm emitters, sandboxed code can intercept host-realm network requests, capturing sensitive Authorization headers and hijacking active TLSSocket streams.
TL;DR
A sandbox escape in vm2 (versions 3.11.3 to 3.11.6) allows untrusted code to access and hook the host process-wide http/https globalAgent. This enables unauthenticated attackers to steal sensitive headers (like Bearer tokens) and hijack active sockets during unrelated host-realm requests.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-668: Exposure of Resource to Wrong Sphere
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 10.0 (Critical)
- EPSS Score: 0.00474 (Percentile: 38.70%)
- Impact: Host Credential Disclosure & Transport Socket Hijacking
- Exploit Status: Proof-of-Concept (PoC) available via official regression test suite
- CISA KEV Status: Not Listed
Affected Systems
- vm2 (npm package)
-
vm2: >= 3.11.3, <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: aa146a7
Implement member-level sanitization for built-in HTTP and HTTPS agents to prevent globalAgent exposure inside the sandbox context.
--- a/lib/builtin.js
+++ b/lib/builtin.js
+// Adds sanitization and overwrites request/get to use sandboxed agents
Exploit Details
- GitHub Security Advisory: Details the vulnerability report, the architectural mechanism of the escape, and provides the reproduction script used as verification.
Mitigation Strategies
- Upgrade vm2 to version 3.11.7 or newer to apply member-level neutralization on built-in HTTP/HTTPS modules.
- Disable the 'http' and 'https' built-in modules inside the NodeVM configuration settings to remove the attack vector entirely.
- Implement outbound network requests outside of the sandbox boundary using a strictly validated custom host-realm API rather than exposing native raw network modules.
- Transition application architectures away from vm2 to modern isolated runtimes, such as isolated-vm or VM containers.
Remediation Steps:
- Locate and audit package.json and project lockfiles for vm2 references within versions 3.11.3 and 3.11.6.
- Run 'npm install [email protected]' or 'yarn upgrade [email protected]' to deploy the patched library version.
- Review initialization scripts of NodeVM to ensure that 'http' and 'https' are absent from the require.builtin array.
- Validate the fix by executing the official regression test to ensure host globalAgent is no longer reachable from the sandbox environment.
References
- GHSA-h85j-hv3c-qfgq Security Advisory
- VulnCheck Vulnerability Report
- Official Patch Commit
- vm2 v3.11.7 Release Tag
- NVD CVE-2026-92940 Details
Read the full report for CVE-2026-92940 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.