Detect vm2 HTTPS Credential Exposure via globalAgent (CVE-2026-92940) in Sumo Logic CSE
Detects presence and exploitation indicators of CVE-2026-92940, a CWE-668 (Exposure of Resource to Wrong Sphere) flaw in the npm package vm2 versions >= 3.11.3 through <= 3.11.6. In affected versions, sandboxed code running inside vm2 can reach the host's https.globalAgent, exposing host HTTPS client credentials (TLS client certificates, private keys, and in-flight TLS session material) to untrusted sandboxed scripts. The CVE carries a CVSS of 10.0 with a public proof-of-concept. This detection surfaces vulnerable vm2 installs via package manifests/lockfiles, Node.js processes loading the vulnerable module, and runtime behaviors consistent with sandbox-driven access to globalAgent and outbound TLS connections. Remediation is upgrade to vm2 >= 3.11.7.
MITRE ATT&CK
Sumo Detection Query
_sourceCategory=*endpoint* ("node_modules/vm2" OR "globalAgent" OR "vm2")
| where (process matches "*node*")
| parse "version=*\"" as vm2version nodrop
| where vm2version matches /3\.11\.[3-6]/ or isNull(vm2version)
| count by _sourceHost, process, vm2version Surfaces endpoint telemetry referencing vm2 node_modules paths, the vulnerable version range, or globalAgent usage.
Data Sources
Required Tables
False Positives & Tuning
- Patched installs still referenced in logs
- SBOM/scanner activity touching vm2 files
- Non-production node executions
Other platforms for CVE-2026-92940
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Install vulnerable vm2 version
Expected signal: File create events for node_modules/vm2/package.json showing version 3.11.6; npm/node process execution.
- Test 2Run vm2 sandbox referencing globalAgent
Expected signal: Node.js process event with command line referencing vm2 and globalAgent.
- Test 3Lockfile pins vulnerable vm2 range
Expected signal: File events for package-lock.json and node_modules\vm2\package.json with version 3.11.5.
References (6)
- https://github.com/patriksimek/vm2/security/advisories/GHSA-h85j-hv3c-qfgq
- https://nvd.nist.gov/vuln/detail/CVE-2026-92940
- https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483daa
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-https-credential-exposure-via-globalagent
- https://github.com/advisories/GHSA-h85j-hv3c-qfgq
Response Playbook
Triage
- Confirm the installed vm2 version on the host (npm ls vm2 / inspect node_modules/vm2/package.json) and verify it falls within >= 3.11.3 and <= 3.11.6.
- Determine whether the vm2 instance executes untrusted or user-supplied code — if the sandbox only runs trusted first-party scripts, exposure risk is materially lower.
- Identify what HTTPS client credentials the host process holds (TLS client certs, private keys, mutual-TLS configs) that https.globalAgent could expose to sandboxed code.
- Review outbound TLS connections initiated by the Node process around the time vm2 executed untrusted code for anomalous destinations.
Containment
- Upgrade vm2 to >= 3.11.7 across all affected services and redeploy; where upgrade is blocked, isolate or disable the sandbox endpoint accepting untrusted code.
- Rotate any HTTPS client certificates, private keys, and credentials that were reachable via the host's https.globalAgent while the vulnerable vm2 was running.
Evidence Collection
- Capture node_modules/vm2/package.json, lockfiles, and the application code paths that instantiate the vm2 sandbox.
- Collect Node.js process telemetry, network connection logs, and any available sandbox audit logs showing scripts executed through vm2.
Escalation Criteria
- !Escalate to IR if the vulnerable vm2 instance executes untrusted/user-submitted code AND the host holds HTTPS client credentials.
- !Escalate if outbound TLS connections to unexpected destinations coincide with sandbox execution, indicating possible credential or traffic exfiltration.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
node_modules/vm2/package.json version string - >
Application source instantiating new VM/NodeVM from vm2 - >
Node.js process network connection logs showing TLS egress - >
Lockfiles (package-lock.json/yarn.lock) pinning vulnerable vm2 range
Tuning Guidance
Suppress hosts confirmed on vm2 >= 3.11.7 by joining against patch/inventory data. Scope file-path matches to production node_modules trees and exclude CI/build and developer test directories. Prioritize alerts where the vm2 sandbox executes untrusted code and the host holds HTTPS client credentials; downgrade matches that are inventory-only with no runtime execution.
Hunting Queries
Enumerate hosts carrying vm2 package artifacts in the vulnerable 3.11.3-3.11.6 range.
DeviceFileEvents | where FolderPath has_cs "node_modules" and FolderPath has_cs "vm2" and FileName == "package.json" | project DeviceName, FolderPath, Timestamp index=osquery name=vm2 | rex field=version "^(?<maj>\d+)\.(?<min>\d+)\.(?<pat>\d+)" | where maj==3 AND min==11 AND pat>=3 AND pat<=6 | table host version path Atomic Red Team Tests
Install vm2 3.11.6 into a lab project to generate detectable package artifacts.
Command
mkdir -p /tmp/vm2lab && cd /tmp/vm2lab && npm init -y >/dev/null 2>&1 && npm install [email protected] Cleanup
rm -rf /tmp/vm2lab Expected Telemetry
File create events for node_modules/vm2/package.json showing version 3.11.6; npm/node process execution.
Expected Detection
KQL/EQL file-path rules match vm2 under node_modules; SPL/osquery inventory flags version 3.11.6 as vulnerable.
Execute a Node script that loads vm2 and references https.globalAgent to simulate credential-sphere access.
Command
cd /tmp/vm2lab && node -e "const {VM}=require('vm2'); const v=new VM(); console.log(v.run('typeof process'));" ; node -e "const https=require('https'); console.log(!!https.globalAgent)" Cleanup
rm -rf /tmp/vm2lab Expected Telemetry
Node.js process event with command line referencing vm2 and globalAgent.
Expected Detection
Process-based KQL/CQL/YARA-L rules match node command line containing vm2 or globalAgent.
Create a lockfile pinning vm2 in the vulnerable range to trigger manifest-based detection.
Command
cmd /c "mkdir C:\vm2lab && cd C:\vm2lab && npm init -y && npm install [email protected]" Cleanup
cmd /c "rmdir /s /q C:\vm2lab" Expected Telemetry
File events for package-lock.json and node_modules\vm2\package.json with version 3.11.5.
Expected Detection
Inventory and file-path detections flag the 3.11.5 install as within the vulnerable 3.11.3-3.11.6 range.