PT-2026-94324 · Npm · Vm2
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.11.0 through 3.11.7
Description
The software fails to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can utilize prototype-walking primitives to access and modify
Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype. This allows host-created typed arrays to observe attacker-controlled properties after the VM.run() function returns.Recommendations
Update vm2 to version 3.11.8.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2