---
id: CVE-2026-92947
title: >-
  vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code,
  allowing disclosure of host memory used by Buffer.from, Buffer.concat, and
  related allocations
summary: >-
  vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code,
  allowing disclosure of host memory used by Buffer.from, Buffer.concat, and
  related allocations. Sandboxed code can read and write to host-realm buffers
  by acquiring A…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L'
cwe:
  - CWE-200
vendor: patriksimek
product: vm2
affected:
  - vm2 < 3.11.7
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T16:18:34.667'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92947'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vm2-before-3.11.7-memory-disclosure-via-buffer-pool
    label: disclosure@vulncheck.com
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-17T15:46:48.210651Z'
ingestedAt: '2026-09-17T14:19:30.987Z'
epss: 0.00432
epssPercentile: 0.37052
---

## Overview

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
