Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-92953: vm2 allows attacker to alter host data structures
CVE-2026-92953 · published 23 days ago
Summary
Versions of vm2 from 3.11.0 up to 3.11.7 do not fully isolate code that runs inside its sandbox. This means a malicious script can change the basic data containers that the main application uses, potentially corrupting or leaking information. Upgrade vm2 to version 3.11.8 or later, or apply the vendor's recommended patch, and review any untrusted code you execute in the sandbox.
What to do
- Update vm2 to version 3.11.8.
- Update patriksimek vm2 to version 3.11.8 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.8 |
| npm | – | vm2 |
>= 3.11.0, <= 3.11.7 >= 3.11.0, < 3.11.8 Fix: upgrade to 3.11.8
|
Original advisory text
vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-3vgf-8m4q-q4qr
- https://www.vulncheck.com/advisories/vm2-3.11.0-through-3.11.7-prototype-polluti...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92953... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92953 Vendor Advisory
- https://github.com/advisories/GHSA-3vgf-8m4q-q4qr
- https://github.com/patriksimek/vm2/commit/92a10fca7b3ca63bb1574b6795540264f6805b... URL
- https://github.com/patriksimek/vm2 Product
- https://github.com/patriksimek/vm2/releases/tag/v3.11.8 URL
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.3
Critical
Type
CWE-913Improper Control of Dynamically-Managed Code Resources
CWE-1321Prototype Pollution
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92953 · NVD
CVE-2026-92953 · MITRE
CVE-2026-92953 · OSV
GHSA-3vgf-8m4q-q4qr · GHSA
GHSA-3vgf-8m4q-q4qr · OSV
Track software like this
Free during beta