Impact
The vulnerability in vm2 prior to version 3.11.7 allows sandboxed JavaScript code to access Node.js’ shared Buffer pool. By acquiring ArrayBuffers from small allocations, the malicious code can read and write host‑realm buffers that originate from Buffer.from, Buffer.concat, and other similar operations. This exposes sensitive host memory, potentially revealing confidential data. In addition, unrestricted read/write capability could be leveraged to corrupt memory used by the host process, leading to a denial‑of‑service condition.
Affected Systems
The affected software is vm2 from the patriksimek project. All releases before 3.11.7 are vulnerable. Users running older vm2 versions to isolate untrusted JavaScript must be aware that the sandbox no longer guarantees isolation of host memory.
Risk and Exploitability
The CVSS base score is 10, indicating a very high severity. No EPSS score is currently available, but the lack of exploitation data does not diminish the risk; the vulnerability remains a critical flaw. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be local or within the application that creates the sandbox, as sandboxed code already has the ability to execute arbitrary JavaScript. If an application can arbitrarily instantiate vm2, a malicious script could exploit the shared buffer pool without additional network access.
OpenCVE Enrichment
Github GHSA