External risk intelligence

vm2 Sandbox Memory Disclosure Via Shared Buffer Pool

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-92947

The vulnerability resides in a sandbox library (vm2) used as a dependency within application code to isolate execution. It is not a standalone service, network gateway, or internet-facing application, but rather a library intended for internal logic processing, making direct public-internet exposure of this specific component highly unlikely in typical deployments.

Information Disclosure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The vm2 sandbox library, prior to version 3.11.7, contains a critical vulnerability that could allow unauthorized access to host memory. This exposure means that sandboxed code could potentially read or write sensitive data residing in the host's memory, leading to data breaches or system instability. The main concern is confirming whether this specific library is in use and exposed in any relevant way.

  • Allows unauthorized memory access.
  • Critical vulnerability in a sandbox library.
  • Confirm relevance and exposure of the library.

Attack Path

How an attacker could exploit the issue

An attacker could leverage this vulnerability by first gaining the ability to execute code within the vm2 sandbox. Once inside the sandbox, they could then interact with Node.js's shared Buffer pool, potentially leading to the exposure or modification of sensitive data residing in the host's memory.

  • Requires sandboxed code execution.
  • Triggered by Buffer pool interaction.
  • Risks sensitive data exposure.

Live Threat

Current exploitation, exposure, and threat context

The vm2 sandbox library can expose Node.js's shared Buffer pool to sandboxed code, potentially allowing access to host memory. This could lead to the disclosure of sensitive data and denial-of-service conditions when supported by the advisory's conditions for Buffer allocations.

  • Host memory used by Buffer allocations.
  • Sandboxed code reads/writes host buffers.
  • Sensitive data disclosure or DoS.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability is in a sandboxed environment library that could lead to memory disclosure, requiring action from teams managing the applications or platforms that utilize this library. The first step is to identify all deployments of this library, assess their business criticality and exposure, and then coordinate remediation efforts.

  • Identify accountable application owners.
  • Verify affected deployment scope.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library used for?

vm2 is a Node.js library designed to create a secure, isolated sandbox environment. Developers use it to run untrusted code by restricting the code's access to the host system's resources and sensitive functionality, theoretically keeping the host environment safe from potentially malicious scripts.

What does CWE-200 mean for CVE-2026-92947?

CWE-200 refers to an Exposure of Sensitive Information. In this vulnerability, the sandbox fails to fully isolate the host system, allowing code running inside the sandbox to access the host's shared Buffer memory pool. This effectively breaks the boundary intended to protect the host, enabling unauthorized reading or writing of memory.

How can an attacker trigger this vulnerability?

An attacker must already have the ability to execute their own code within the vm2 sandbox environment. Once inside, they perform specific operations involving Node.js Buffer allocations. The vulnerability does not trigger through simple network requests to an application unless those requests directly inject and execute code inside the sandboxed component.

Do I need to worry about this if my app is internal?

Halo Surface Signal indicates that vm2 is a library, not an internet-facing service, making direct public access unlikely. However, if your application processes untrusted user input within a vm2 sandbox, the risk persists regardless of whether the application itself is internal or external, as the sandbox boundary is what matters.

What are the first steps to address this CVE?

Begin by auditing your dependency manifests to identify applications utilizing vm2 versions earlier than 3.11.7. Once located, coordinate with the respective application owners to verify how the sandbox is utilized and prioritize upgrading the library to version 3.11.7 or later to patch the memory disclosure flaw.

References