{"id":"CVE-2026-92953","published":"2026-09-17T14:18:01.160","lastModified":"2026-09-18T20:17:31.113","description":"vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H","cwes":["CWE-913"],"vendors":[],"products":[],"references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-3vgf-8m4q-q4qr","tags":[]},{"url":"https://www.vulncheck.com/advisories/vm2-3.11.0-through-3.11.7-prototype-pollution-via-typedarray","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-3vgf-8m4q-q4qr","tags":[]}],"exploitRefs":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-3vgf-8m4q-q4qr","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-3vgf-8m4q-q4qr","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows attackers to modify host TypedArray and ArrayBuffer prototypes, leading to potential host-created typed arrays observing attacker-controlled properties. This can compromise data integrity and security.","exploitability":"Exploitation is relatively straightforward given the preconditions of running the affected vm2 version and having access to prototype-walking primitives.","blast_radius":"If exploited, this could lead to significant data corruption and security breaches, impacting any application relying on host-created typed arrays.","remediation":"Upgrade to vm2 version 3.11.8 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","data-integrity","web","array","typedarray"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:55:40.809Z"}}