chiprook
← Security
SecurityOctober 2, 2026, 08:30

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets

A critical vulnerability in the Node.js sandbox library vm2 (3.11.3–3.11.6, CVSS 10.0) lets sandboxed code reach the host process-wide http.globalAgent and https.globalAgent, intercept host network requests, capture Authorization headers and hijack active TLSSocket streams. It is fixed in vm2 3.11.7.

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets
#Vm2#Node.js
Read next
Security

CVE-2026-92948: vm2 sandbox escape via node:test rated 9.9

Security

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Security

CVE-2026-92951: vm2 sandbox escape via external package allowlist bypass

Security

MemOS supply-chain worm sckit steals developer tokens