PT-2026-94318 · Npm · Vm2
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.7
Description
The software exposes the shared Buffer pool of Node.js to sandboxed code. This allows sandboxed code to acquire ArrayBuffers from small allocations to read and write to host-realm buffers. This issue can lead to the disclosure of host memory used by
Buffer.from, Buffer.concat, and related allocations, resulting in sensitive data exposure and potential denial-of-service.Recommendations
Update to version 3.11.7 or later.
Exploit
Fix
DoS
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2