PT-2026-94318 · Npm · Vm2

·

CVE-2026-92947

·

Published

2026-08-25

·

Updated

2026-09-17

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.7
Description The software exposes the shared Buffer pool of Node.js to sandboxed code. This allows sandboxed code to acquire ArrayBuffers from small allocations to read and write to host-realm buffers. This issue can lead to the disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations, resulting in sensitive data exposure and potential denial-of-service.
Recommendations Update to version 3.11.7 or later.

Exploit

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14942
CVE-2026-92947
GHSA-FCQC-726X-5WFC

Affected Products

Vm2