criticalCVSS 10Vulnerability

CVE-2026-92947

### Summary Sandboxed code is able to disclose host memory used by small allocations by `Buffer.from`, `Buffer.concat`. ### Details vm2 exposes `Buffer` object to sandboxed code by default. Small [`Buffer` allocations](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize) (for example, [Buffer.allocUnsafe()](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize), [Buffer.from(array)](https://nodejs.org/api/buffer.html#static-method-bufferfromarray), [Buffer.from(string)](https://nodejs.org/api/buffer.html#static-method-bufferfromstring-encoding), and [Buffer.concat()](https://nodejs.org/api/buffer.html#static-method-bufferconcatlist-totallength)) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above. ### PoC Tested against `[email protected]` in the node REPL. ```javascript Buffer.from('host-memory-should-not-leak-to-sandbox') new (require('vm2').VM)().run(`Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString('ascii')`) ``` <img width="1044" height="104" alt="Screenshot 2026-07-23 at 17 54 15" src="https://github.com/user-attachments/assets/987b860c-6702-4818-bfaa-c77919c777e5" /> ### Impact Since sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-of-service.

Properties

severity
critical
summary
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
epss_score
0.00482
cvss_score
10
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:34:35Z
source_url
https://github.com/advisories/GHSA-fcqc-726x-5wfc
ghsa_updated
2026-10-05T22:34:36Z
ghsa_id
GHSA-fcqc-726x-5wfc
last_source
FIRST EPSS
cve_id
CVE-2026-92947
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.39405

Related Entities (7)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (3)

→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
→[Weakness]Exposure of Resource to Wrong Sphere
→[Weakness]Improper Isolation or Compartmentalization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92947 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal