{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-100722/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-92947"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vm2 (\u003c= 3.11.6)","vm2 (\u003c= 3.12.1)"],"_cs_severities":["critical"],"_cs_tags":["sandbox-escape","nodejs","vulnerability","privilege-escalation","denial-of-service","sandbox","javascript","cve-2026-100722"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe vm2 library, a popular JavaScript sandbox for Node.js, contains a critical security vulnerability (CVE-2026-92947) that enables sandbox escape. The flaw arises because vm2 exposes the Node.js \u003ccode\u003eBuffer\u003c/code\u003e object to sandboxed code by default. In Node.js, small \u003ccode\u003eBuffer\u003c/code\u003e allocations - including \u003ccode\u003eBuffer.from\u003c/code\u003e, \u003ccode\u003eBuffer.concat\u003c/code\u003e, and \u003ccode\u003eBuffer.allocUnsafe\u003c/code\u003e - utilize a shared internal memory pool. Because the sandbox and host share this pool, an attacker capable of executing arbitrary code within the vm2 sandbox can reference the underlying \u003ccode\u003eArrayBuffer\u003c/code\u003e used by the host process. This allows the attacker to read host memory, leading to sensitive data disclosure, or write to host memory, potentially corrupting application state and leading to denial-of-service or further privilege escalation. This affects all versions of vm2 up to and including 3.11.6.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for the cross-realm disclosure of sensitive data processed by the host application, such as authentication tokens, user data, or API keys. Furthermore, the ability for an attacker to perform unauthorized writes to the host-realm memory provides a vector for full sandbox escape, as an attacker can manipulate host process objects or execute arbitrary code outside the restricted sandbox environment. This poses a significant risk to any application that uses vm2 to evaluate untrusted user-provided JavaScript code.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the vm2 package to the latest version that addresses CVE-2026-92947, or if no patch is available, migrate to a more secure sandboxing alternative.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and sanitization for all code passed into the vm2 sandbox, though this is not a complete mitigation for the identified memory-sharing flaw.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege to the Node.js host process by limiting access to sensitive memory, files, and network resources to reduce the potential impact of a sandbox escape.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:45:58Z","date_published":"2026-10-06T00:44:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vm2-sandbox-escape/","summary":"A vulnerability in the vm2 library (CVE-2026-92947) allows sandboxed code to bypass security boundaries by reading and writing to the host-realm memory shared through Node.js Buffer pools.","title":"Critical Sandbox Escape in vm2 via Node.js Buffer Pool","url":"https://feed.craftedsignal.io/briefs/2026-10-vm2-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-100722","version":"https://jsonfeed.org/version/1.1"}