CVE-2026-47683Disclosure

MEDIUMCVSS 8.7 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowing sandbox code to perform large synchronous host external-memory allocations that bypass the configured cap and can exhaust the host process. This issue is fixed in version 3.11.6.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 2PoC Mentioned / Linked · 2026-08-18: 1Exploit Tool / Code · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 208-18
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 vm2, Memory Exhaustion DoS (bufferAllocLimit Bypass), #CVE-2026-47683 (High) -DC-Aug2026-1560 https://dailycve.com/vm2-memory-exhaustion-dos-bufferalloclimit-bypass-cve-2026-47683-high-dc-aug2026-1560/

    Post summary

    A new memory‑exhaustion denial‑of‑service vulnerability (CVE‑2026‑47683) in vm2 is announced, with a brief technical description and a link to DailyCVE for details, but no PoC, exploit, patch, or active‑exploitation information.

    0000022
    228 followersView on X
  • Upwind Security MDR@UpwindMDR
    Exploit

    🚨Critical - vm2 sandbox escape → host RCE, plus alloc-limit DoS (CVE-2026-47698, CVE-2026-47686, GHSA-m5w8-4gq2-6f8x, CVE-2026-47683, GHSA-v836-6xw4-9cx3) Five flaws in vm2 < 3.11.6. Escape → host RCE: the proto-mutator fix is bypassable via http://indirectcall.call(indirectcall, dangerousmutator, ...); handleException() doesn't sanitize Error.cause, leaking host objects like process; DANGEROUS_BUILTINS omits os/dns, so builtin: ['*'] allows a process-wide DNS hijack. DoS: bufferAllocLimit bypassable via Buffer.concat and TypedArray constructors. 👉Affected: vm2 (npm) ≤ 3.11.5 | Upgrade to 3.11.6

    Post summary

    A set of five critical vm2 vulnerabilities enabling sandbox escape and host RCE with documented bypass techniques, mitigated by upgrading to version 3.11.6.

    0000089
    291 followersView on X

Explore more