CRITICAL 9.3 NVD
CVE-2026-92953
vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking pri
vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-3vgf-8m4q-q4qr
- https://www.vulncheck.com/advisories/vm2-3.11.0-through-3.11.7-prototype-pollution-via-typ
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-17 via NVD.
Risk Timeline
CVE Disclosed2026-09-17 · -1 days ago
Remediation Resources
vulnfeed aggregates 12865 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.