CVE-2026-92953
CRITICAL
NVD
CVSS Score
10
Severity
CRITICAL
Published
Sep 17, 2026
Vendor
unknown
Description
vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.