Duplicate Advisory: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
Critical severity
GitHub Reviewed
Published
Sep 17, 2026
to the GitHub Advisory Database
•
Updated Oct 5, 2026
Withdrawn
This advisory was withdrawn on Oct 5, 2026
Description
Published by the National Vulnerability Database
Sep 17, 2026
Published to the GitHub Advisory Database
Sep 17, 2026
Last updated
Oct 5, 2026
Reviewed
Oct 5, 2026
Withdrawn
Oct 5, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-3vgf-8m4q-q4qr. This link is maintained to preserve external references.
Original Description
vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.
References