{"id":"GHSA-fcqc-726x-5wfc","summary":"vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool","details":"### Summary\nSandboxed code is able to disclose host memory used by small allocations by `Buffer.from`, `Buffer.concat`.\n\n### Details\nvm2 exposes `Buffer` object to sandboxed code by default. Small [`Buffer` allocations](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize) (for example, [Buffer.allocUnsafe()](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize), [Buffer.from(array)](https://nodejs.org/api/buffer.html#static-method-bufferfromarray), [Buffer.from(string)](https://nodejs.org/api/buffer.html#static-method-bufferfromstring-encoding), and [Buffer.concat()](https://nodejs.org/api/buffer.html#static-method-bufferconcatlist-totallength)) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above.\n\n### PoC\nTested against `vm2@3.11.5` in the node REPL.\n```javascript\nBuffer.from('host-memory-should-not-leak-to-sandbox')\nnew (require('vm2').VM)().run(`Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString('ascii')`)\n```\n\n\u003cimg width=\"1044\" height=\"104\" alt=\"Screenshot 2026-07-23 at 17 54 15\" src=\"https://github.com/user-attachments/assets/987b860c-6702-4818-bfaa-c77919c777e5\" /\u003e\n\n### Impact\nSince sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-of-service.","aliases":["CVE-2026-92947"],"modified":"2026-10-05T22:45:05.487849035Z","published":"2026-10-05T22:34:35Z","database_specific":{"cwe_ids":["CWE-200","CWE-653","CWE-668"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-10-05T22:34:35Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92947"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/4f2508abeb252aa86eb6761c78b3b000248fb089"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.7"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vm2-before-3.11.7-memory-disclosure-via-buffer-pool"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.11.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-fcqc-726x-5wfc/GHSA-fcqc-726x-5wfc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"}]}