OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100723

HIGH · CVSS 7.5 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the vm2 library versions prior to 3.12.2, specifically when the Node.js zlib module is exposed to untrusted guest code. This flaw allows an attacker to manipulate Buffers, potentially leading to unauthorized access and modification of host memory, which can result in data disclosure and corruption. Organizations utilizing vm2 for sandboxing untrusted code, particularly those exposing the zlib module, should prioritize patching to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100723
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is the entire pool. Untrusted guest code can construct a full-width view of that ArrayBuffer (Buffer.from(result.buffer, 0, result.buffer.byteLength)) to read and modify bytes belonging to unrelated host buffers, disclosing and corrupting host-realm memory across the sandbox boundary.