GHSA-43rv-jrfh-9mrrMedium· 7.5▾ SunlitDuplicate Advisory: vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary
▾ Sunlit zone — Low / medium · no exploitation signal
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-489w-w794-jq94. This link is maintained to preserve external references.
vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is the entire pool. Untrusted guest code can construct a full-width view of that ArrayBuffer (Buffer.from(result.buffer, 0, result.buffer.byteLength)) to read and modify bytes belonging to unrelated host buffers, disclosing and corrupting host-realm memory across the sandbox boundary.
vm2 < 3.12.2Upgrade to a patched release:
vm2 3.12.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100723High· 7.5vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules
CVE-2026-92947Critical· 10.0vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations
GHSA-2vh9-cv26-p97mMedium· 5.8Duplicate Advisory: vm2: util.getCallSites() bypasses GHSA-v27g host-frame redaction, leaks host call stack
GHSA-x5qg-8pq6-39h6Critical· 10.0Duplicate Advisory: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
CVE-2026-92933Medium· 5.8vm2 is a sandbox for running untrusted Node.js code
GHSA-m5w8-4gq2-6f8xCritical· 10.0vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)