Skip to content

Explain released Agent isolation and indirect req.agent access for GHSA-h85j-hv3c-qfgq - #10123

Open
nazeeh111 wants to merge 1 commit into
github:nazeeh111/advisory-improvement-10123from
nazeeh111:vm2-cve-2026-92940-agent-isolation-clarification
Open

nazeeh111 wants to merge 1 commit into
github:nazeeh111/advisory-improvement-10123from
nazeeh111:vm2-cve-2026-92940-agent-isolation-clarification

Conversation

@nazeeh111

Copy link
Copy Markdown

Explain released Agent isolation and indirect req.agent access for GHSA-h85j-hv3c-qfgq

The advisory explains direct access to the host https.globalAgent, but its public fix also addresses an indirect access path through the agent property of a request returned by https.request(). Replacing only the exposed globalAgent property leaves the original request helpers using the host default Agent internally.

This appends a short remediation section identifying the existing 3.11.7 fix: the exposed Agent is separate, and https.request()/https.get() use it by default while preserving caller-supplied agents. This matters when evaluating a local workaround that masks only the visible property. The original report, affected ranges, severity, references and all other fields remain unchanged. No HTTP affected range, additional runtime, original discovery claim or credit is added.

Public primary evidence:

  • Vendor advisory identifies the original HTTPS issue, affected 3.11.3 through 3.11.6 and fixed 3.11.7.
  • Maintainer fix identifies the indirect req.agent route and defaults both request helpers to the dedicated Agent. Its regression test explicitly covers this variant and retained HTTPS helpers.
  • 3.11.7 release identifies this advisory among the shipped fixes; tagged implementation contains that Agent handling.

Validation: original and proposed records pass the OSV schema; the only changed field is details. Exact GHSA and CVE PR searches returned zero results during preparation. No exploit or upstream test was executed locally.

Prepared with Codex assistance and public source analysis. This improves an already disclosed advisory and does not claim original vulnerability discovery.

@github-actions
github-actions Bot changed the base branch from main to nazeeh111/advisory-improvement-10123 October 3, 2026 04:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant