CVE-2026-92953

CRITICAL Status: Deferred

CVSS Scores

CVSS v3.x Base Score
10.0
CRITICAL

Description

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.

Published
September 17, 2026 2:18 PM
Last Modified
September 17, 2026 2:18 PM
Source
[email protected]

Weaknesses (CWE)

CWE-913

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.