<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T10:12:09.623673+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-92947</id>
    <title>CVE-2026-92947 — vm2 before 3.11.7 Memory Disclosure via Buffer Pool</title>
    <updated>2026-10-08T10:12:09.654745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> patriksimek vm2</p>
<p>vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-92947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fcqc-726x-5wfc</id>
    <title>GHSA-fcqc-726x-5wfc — vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool</title>
    <updated>2026-10-08T10:12:09.654817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>### Summary
Sandboxed code is able to disclose host memory used by small allocations by `Buffer.from`, `Buffer.concat`.</p>
<p>### Details
vm2 exposes `Buffer` object to sandboxed code by default. Small [`Buffer` allocations](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize) (for example, [Buffer.allocUnsafe()](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize), [Buffer.from(array)](https://nodejs.org/api/buffer.html#static-method-bufferfromarray), [Buffer.from(string)](https://nodejs.org/api/buffer.html#static-method-bufferfromstring-encoding), and [Buffer.concat()](https://nodejs.org/api/buffer.html#static-method-bufferconcatlist-totallength)) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above.</p>
<p>### PoC
Tested against `vm2@3.11.5` in the node REPL.
```javascript
Buffer.from('host-memory-should-not-leak-to-sandbox')
new (require('vm2').VM)().run(`Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString('ascii')`)
```</p>
<p>&lt;img width="1044" height="104" alt="Screenshot 2026-07-23 at 17 54 15" src="https://github.com/user-attachments/assets/987b860c-6702-4818-bfaa-c77919c777e5" /&gt;</p>
<p>### Impact
Since sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fcqc-726x-5wfc"/>
  </entry>
</feed>
