Tag
A vulnerability in the vm2 library (CVE-2026-92947) allows sandboxed code to bypass security boundaries by reading and writing to the host-realm memory shared through Node.js Buffer pools.