GHSA-5v7w-95g5-pj6q

Suggest an improvement
Source
https://github.com/advisories/GHSA-5v7w-95g5-pj6q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-5v7w-95g5-pj6q/GHSA-5v7w-95g5-pj6q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5v7w-95g5-pj6q
Withdrawn
2026-10-05T22:45:04Z
Published
2026-09-17T15:32:16Z
Modified
2026-10-05T23:00:04Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H CVSS Calculator
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-3vgf-8m4q-q4qr. This link is maintained to preserve external references.

Original Description

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.

Database specific
{
    "cwe_ids":  [
        "CWE-913"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:45:04Z",
    "nvd_published_at":  "2026-09-17T14:18:01Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / vm2

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.11.0
Last Affected
3.11.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-5v7w-95g5-pj6q/GHSA-5v7w-95g5-pj6q.json"