Description
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in vm2 prior to version 3.11.7 allows sandboxed JavaScript code to access Node.js’ shared Buffer pool. By acquiring ArrayBuffers from small allocations, the malicious code can read and write host‑realm buffers that originate from Buffer.from, Buffer.concat, and other similar operations. This exposes sensitive host memory, potentially revealing confidential data. In addition, unrestricted read/write capability could be leveraged to corrupt memory used by the host process, leading to a denial‑of‑service condition.

Affected Systems

The affected software is vm2 from the patriksimek project. All releases before 3.11.7 are vulnerable. Users running older vm2 versions to isolate untrusted JavaScript must be aware that the sandbox no longer guarantees isolation of host memory.

Risk and Exploitability

The CVSS base score is 10, indicating a very high severity. No EPSS score is currently available, but the lack of exploitation data does not diminish the risk; the vulnerability remains a critical flaw. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be local or within the application that creates the sandbox, as sandboxed code already has the ability to execute arbitrary JavaScript. If an application can arbitrarily instantiate vm2, a malicious script could exploit the shared buffer pool without additional network access.

Generated by OpenCVE AI on September 17, 2026 at 23:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later to remove exposure of the shared Buffer pool.
  • Reconfigure the vm2 sandbox to disable shared buffer access, such as disabling the 'shared' flag or restricting ArrayBuffer exposure.
  • Audit all code paths that generate Buffer objects from user input and enforce strict input validation to mitigate accidental memory disclosure.

Generated by OpenCVE AI on September 17, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fcqc-726x-5wfc vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.
Title vm2 before 3.11.7 Memory Disclosure via Buffer Pool
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:47:14.117Z

Reserved: 2026-09-17T12:43:03.568Z

Link: CVE-2026-92947

cve-icon Vulnrichment

Updated: 2026-09-17T15:47:06.803Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:00.140

Modified: 2026-09-17T16:18:34.667

Link: CVE-2026-92947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor