Vulnerability GHSA-fcqc-726x-5wfc

Critical
CRITICAL RISK
CVSS Score: 10.0
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
8 hours ago
October 05, 2026 at 10:34 PM UTC
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
0.1.0 - 3.11.6
0.1.0 - 3.11.6

Summary

vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool

Details

Summary

Sandboxed code is able to disclose host memory used by small allocations by Buffer.from, Buffer.concat.

Details

vm2 exposes Buffer object to sandboxed code by default. Small Buffer allocations (for example, Buffer.allocUnsafe(), Buffer.from(array), Buffer.from(string), and Buffer.concat()) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above.

PoC

Tested against [email protected] in the node REPL.

Buffer.from('host-memory-should-not-leak-to-sandbox')
new (require('vm2').VM)().run(`Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString('ascii')`)
Screenshot 2026-07-23 at 17 54 15

Impact

Since sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-of-service.

Impacted packages

Timeline

Published
8 hours ago
October 05, 2026 at 10:34 PM UTC
Fixed (3.11.7)
Unknown
Unknown
Last Modified
8 hours ago
October 05, 2026 at 10:45 PM UTC