---
id: GHSA-x5qg-8pq6-39h6
title: >-
  Duplicate Advisory: Sandboxed code can read and write host-realm memory via
  Node's shared Buffer pool
summary: >-
  Duplicate Advisory: Sandboxed code can read and write host-realm memory via
  Node's shared Buffer pool
severity: critical
cvss: 10
cwe:
  - CWE-200
vendor: vm2
product: vm2
ecosystem: npm
affected:
  - vm2 <= 3.11.6
published: '2026-09-17'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T22:34:31Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-x5qg-8pq6-39h6'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92947'
  - url: >-
      https://www.vulncheck.com/advisories/vm2-before-3.11.7-memory-disclosure-via-buffer-pool
  - url: 'https://github.com/advisories/GHSA-x5qg-8pq6-39h6'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-05T22:35:24.743Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-fcqc-726x-5wfc This link is maintained to preserve external references.

## Original Description
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.

## Affected packages

- `vm2 <= 3.11.6`

## Remediation

Refer to the advisory for the patched release.
