CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets
A critical vulnerability in the Node.js sandbox library vm2 (3.11.3–3.11.6, CVSS 10.0) lets sandboxed code reach the host process-wide http.globalAgent and https.globalAgent, intercept host network requests, capture Authorization headers and hijack active TLSSocket streams. It is fixed in vm2 3.11.7.
- CVSS 10.0, CWE-668; PoC available via the official regression test suite
- Affects vm2 3.11.3–3.11.6, patched in 3.11.7
- Attackers can steal Bearer tokens and hijack live TLS connections
- Mitigation: disable http/https built-ins in NodeVM or move to isolated-vm
Read next
Security