GHSA-fcqc-726x-5wfc

Suggest an improvement
Source
https://github.com/advisories/GHSA-fcqc-726x-5wfc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-fcqc-726x-5wfc/GHSA-fcqc-726x-5wfc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fcqc-726x-5wfc
Aliases
Downstream
Published
2026-10-05T22:34:35Z
Modified
2026-10-05T22:45:05Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
Details

Summary

Sandboxed code is able to disclose host memory used by small allocations by Buffer.from, Buffer.concat.

Details

vm2 exposes Buffer object to sandboxed code by default. Small Buffer allocations (for example, Buffer.allocUnsafe(), Buffer.from(array), Buffer.from(string), and Buffer.concat()) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above.

PoC

Tested against vm2@3.11.5 in the node REPL.

Buffer.from('host-memory-should-not-leak-to-sandbox')
new (require('vm2').VM)().run(`Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString('ascii')`)
Screenshot 2026-07-23 at 17 54 15

Impact

Since sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-of-service.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-653",
        "CWE-668"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-05T22:34:35Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

npm / vm2

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.7

Database specific

last_known_affected_version_range
"<= 3.11.6"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-fcqc-726x-5wfc/GHSA-fcqc-726x-5wfc.json"