Sceawere

Vulnerability Detail

CVE-2026-100723UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

vm2 Sandbox Buffer Prototype Escape

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
patriksimek
Product
vm2
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is the entire pool. Untrusted guest code can construct a full-width view of that ArrayBuffer (Buffer.from(result.buffer, 0, result.buffer.byteLength)) to read and modify bytes belonging to unrelated host buffers, disclosing and corrupting host-realm memory across the sandbox boundary.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-27T02:17:19.373Z",
  "pubdate": "2026-09-27T02:17:19.373Z",
  "executiveSummary": "This vulnerability involves an improper sandbox boundary enforcement within the vm2 Node.js sandboxing library, specifically concerning the handling of Buffer objects returned from host builtin modules.\nThe vulnerability allows an untrusted guest script to achieve cross-realm memory access, leading to arbitrary host-realm memory disclosure and corruption.\nThe flaw affects vm2 versions prior to 3.12.2 and is triggered when the Node.js zlib module is explicitly exposed to the sandbox via the NodeVM builtin allowlist.\nAn attacker capable of executing code within the sandbox environment can leverage this defect to bypass security isolation, potentially leading to complete host system compromise, privilege escalation, or unauthorized access to sensitive data processed by the host.\nExploitation is straightforward once the zlib module is enabled, requiring no further authentication or complex prerequisites within the sandbox environment.",
  "technicalDetails": "The root cause of this vulnerability is the failure of vm2 to enforce the Buffer backing-store ownership invariant for Buffers returned from Node.js host builtin modules.\nIn Node.js, small Buffers are often allocated from a shared pool to optimize performance. When zlib.deflateSync is called, it may return a Buffer instance that is a view into this shared pool, where the underlying ArrayBuffer represents the entire pool rather than the specific Buffer instance.\nThe vm2 sandbox maintains a security invariant for Buffers that requires byteOffset to be 0 and the byteLength to match the length of the buffer. By failing to validate this invariant for objects returned from host builtins like zlib, vm2 allows a guest-side reference to an ArrayBuffer that contains memory belonging to other parts of the host process.\nThe attack flow proceeds as follows: First, the attacker ensures that the zlib module is available in the NodeVM instance through the builtin allowlist. Second, the attacker invokes zlib.deflateSync, which returns a Buffer backed by the shared pool. Third, the attacker extracts the underlying ArrayBuffer from this returned Buffer object. Because the invariant check is bypassed, the attacker can then construct a new Buffer (or TypedArray) using this shared ArrayBuffer with an arbitrary offset and length covering the entire memory pool.\nThis constructed view provides the guest code with read and write access to the host's memory, including portions of the heap belonging to unrelated objects or host-realm logic. An attacker can use this primitive to scan for sensitive tokens, manipulate host-side variables, or overwrite pointers to redirect control flow, effectively breaking out of the intended sandbox security context.\nThis vulnerability highlights a critical breakdown in object mediation between the host and guest realms, specifically where host-allocated objects rely on internal memory management structures that are not adequately isolated or sanitized by the sandbox proxy layer before being passed into the restricted environment.\nAffected versions are strictly those before 3.12.2. There is no requirement for network exposure, as the vulnerability is inherent to the execution of untrusted JavaScript code within the vm2-managed sandbox."
}
CVE-2026-100723: vm2 Sandbox Buffer Prototype Escape (HIGH Severity, CVSS: 7.5) | Sceawere