Impact
The vulnerability resides in vm2 before version 3.11.6, a memory exhaustion weakness (CWE-770) where the module fails to enforce the bufferAllocLimit parameter for ArrayBuffer, SharedArrayBuffer, and TypedArray constructors. An attacker can exploit V8 intrinsics to allocate host memory arbitrarily, exhausting the process and causing out‑of‑memory conditions. The result is a denial of service that undermines the availability of the sandboxed application.
Affected Systems
This issue affects the vm2 library supplied by patriksimek, impacting all installations that use any version prior to 3.11.6. Any deployment that creates or manipulates the specified buffers within a vm2 sandbox is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires the attacker to execute JavaScript inside the sandboxed environment, as the description does not mention a network‑based vector. Because the flaw can cause a complete process crash, the risk remains significant until mitigated.
OpenCVE Enrichment