CVE-2026-100723 Details
Description
vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is the entire pool. Untrusted guest code can construct a full-width view of that ArrayBuffer (Buffer.from(result.buffer, 0, result.buffer.byteLength)) to read and modify bytes belonging to unrelated host buffers, disclosing and corrupting host-realm memory across the sandbox boundary.
A vulnerability exists in vm2 versions prior to 3.12.2, where the library fails to enforce proper ownership invariants on Buffers returned from host-built-in modules. This issue is particularly relevant when Node's zlib module is exposed to untrusted code via vm2's NodeVM. The problem arises because zlib.deflateSync can return a Buffer that is backed by Node's shared small-buffer pool, which includes bytes from unrelated host buffers. This allows guest code to read and modify sensitive host memory, crossing the sandbox boundary and potentially leading to the corruption of important data such as database rows or session tokens.
Users can upgrade to vm2 version 3.12.2 or later, where this vulnerability has been addressed. The patch involves enforcing the Buffer ownership invariant for all Buffer-returning host builtins, ensuring that sandboxed code cannot access pooled host memory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vm2 | <= 3.12.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion