GHSA-fcqc-726x-5wfc: Infoleak

Published Oct 5, 2026
·
Updated

Summary Sandboxed code is able to disclose host memory used by small allocations by Buffer.from, Buffer.concat.

Details vm2 exposes Buffer object to sandboxed code by default. Small Buffer allocations (for example, Buffer.allocUnsafe(), Buffer.from(array), Buffer.from(string), and Buffer.concat()) use the same Buffer pool, which is shared with the sandbox. This allows sandboxed code to disclose host memory used by the functions listed above.

PoC Tested against vm2@3.11.5 in the node REPL. javascript Buffer.from('host-memory-should-not-leak-to-sandbox') new (require('vm2').VM)().run(Buffer.from(Buffer.from([0]).buffer, 0, Buffer.from([0]).buffer.byteLength).toString('ascii'))

<img width="1044" height="104" alt="Screenshot 2026-07-23 at 17 54 15" src="https://github.com/user-attachments/assets/987b860c-6702-4818-bfaa-c77919c777e5" />

Impact Since sandbox acquires an ArrayBuffer that is used by the host, it can disclose sensitive data going through functions mentioned above and even write to these buffers, which can lead to sensitive data exposure and potentially denial-of-service.

Affected Software

1 affected componentFixes available
npm/vm2<=3.11.6
3.11.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/vm2 to a version that resolves this vulnerability.

    Fixed in 3.11.7

Event History

Oct 5, 2026
Advisory Published
via GitHub·10:34 PM
Data Sourced
via GitHub·10:34 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using npm/vm2 that run untrusted or less-trusted code in a VM are exposed, because that sandboxed code can access the Buffer object. The disclosure concerns host memory associated with small Buffer-pool allocations.

2

What does an attacker need to exploit it?

An attacker needs the ability to execute code inside a vm2 sandbox. No privileges or user interaction are indicated by the provided severity vector.

3

Is the default sandbox configuration affected?

Yes. vm2 exposes Buffer to sandboxed code by default, allowing sandbox code to access the shared Buffer pool.

4

What data could be disclosed?

Sandboxed code may disclose host memory used by small allocations made through Buffer.allocUnsafe(), Buffer.from(array), Buffer.from(string), or Buffer.concat(). The provided proof of concept was tested with vm2 version 3.11.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203