Exposure of Resource to Wrong Sphere Affecting vm2 package, versions <3.12.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.32% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-VM2-20158392
  • published27 Sept 2026
  • disclosed27 Sept 2026
  • creditUnknown

Introduced: 27 Sep 2026

NewCVE-2026-100723  (opens in a new tab)
CWE-668  (opens in a new tab)

How to fix?

Upgrade vm2 to version 3.12.2 or higher.

Overview

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules.

Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere via the bufferFrom and related Buffer factory functions in lib/setup-sandbox.js, where Node.js serves small Buffer.from(...) allocations out of a single shared 64 KiB backing ArrayBuffer pool. A sandbox attacker can call Buffer.from([0]).buffer to obtain the entire shared pool ArrayBuffer, then construct a full-width view with Buffer.from(ab, 0, ab.byteLength) to read and overwrite every host-realm buffer that shares the pool, including secrets, database rows, and tokens held by the host process. This constitutes a full confidentiality and integrity escape from the sandbox.

CVSS Base Scores

version 4.0
version 3.1