Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-92947: vm2 lets sandboxed code read and change host memory

CVE-2026-92947 · published 23 days ago
Summary

The vm2 library, up to version 3.11.6, lets code that is supposed to run in isolation access the main program's memory. This can expose sensitive information or cause the application to stop working. Upgrade vm2 to the newest version to close the gap.

What to do
  • Update vm2 to version 3.11.7.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 <= 3.11.6
Fix: upgrade to 3.11.7
Original advisory text
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-200Information Exposure
CWE-653Improper Isolation or Compartmentalization
CWE-668Exposure of Resource to Wrong Sphere
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92947 · MITRE
Track software like this
Free during beta