<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:20:57 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-92947 — vm2 before 3.11.7 Memory Disclosure via Buffer Pool</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-92947</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; patriksimek vm2&lt;/p&gt;
&lt;p&gt;vm2 before 3.11.7 exposes Node&amp;#39;s shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; patriksimek vm2&lt;/p&gt;
&lt;p&gt;vm2 before 3.11.7 exposes Node&amp;#39;s shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-92947</guid>
    </item>
    <item>
      <title>GHSA-fcqc-726x-5wfc — vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fcqc-726x-5wfc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary
Sandboxed code is able to disclose host memory used by small allocations by `Buffer.from`, `Buffer.concat`.&lt;/p&gt;
&lt;p&gt;### Details
vm2 exposes `Buffer` object to sandboxed code by default. Small [`Buffer` allocations](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize) (for example, [Buffer.allocUnsafe()](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize), [Buffer.from(array)](https://nodejs.org/api/buffer.html#static-method-bufferfromarray), [Buffer.from(string)](https://nodejs.org/api/buffer.html#static-method-bufferfromstring-encoding), and [Buffer.concat()](https://nodejs.org/api/buffer.html#static-method-bufferconcatlist-totallength)) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above.&lt;/p&gt;
&lt;p&gt;### PoC
Tested against `vm2@3.11.5` in the node REPL.
```javascript
Buffer.from(&amp;#39;host-memory-should-not-leak-to-sandbox&amp;#39;)
new (require(&amp;#39;vm2&amp;#39;).VM)().run(`Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString(&amp;#39;ascii&amp;#39;)`)
```&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1044&amp;#34; height=&amp;#34;104&amp;#34; alt=&amp;#34;Screenshot 2026-07-23 at 17 54 15&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/987b860c-6702-4818-bfaa-c77919c777e5&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Impact
Since sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary
Sandboxed code is able to disclose host memory used by small allocations by `Buffer.from`, `Buffer.concat`.&lt;/p&gt;
&lt;p&gt;### Details
vm2 exposes `Buffer` object to sandboxed code by default. Small [`Buffer` allocations](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize) (for example, [Buffer.allocUnsafe()](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize), [Buffer.from(array)](https://nodejs.org/api/buffer.html#static-method-bufferfromarray), [Buffer.from(string)](https://nodejs.org/api/buffer.html#static-method-bufferfromstring-encoding), and [Buffer.concat()](https://nodejs.org/api/buffer.html#static-method-bufferconcatlist-totallength)) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above.&lt;/p&gt;
&lt;p&gt;### PoC
Tested against `vm2@3.11.5` in the node REPL.
```javascript
Buffer.from(&amp;#39;host-memory-should-not-leak-to-sandbox&amp;#39;)
new (require(&amp;#39;vm2&amp;#39;).VM)().run(`Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString(&amp;#39;ascii&amp;#39;)`)
```&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1044&amp;#34; height=&amp;#34;104&amp;#34; alt=&amp;#34;Screenshot 2026-07-23 at 17 54 15&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/987b860c-6702-4818-bfaa-c77919c777e5&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Impact
Since sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fcqc-726x-5wfc</guid>
    </item>
  </channel>
</rss>
