CVE Vulnerabilities

CVE-2026-92953

Improper Control of Dynamically-Managed Code Resources

Published: Sep 17, 2026 | Modified: Sep 18, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
9.3 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Developer Hub 1.10RedHatrhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697*
Red Hat Developer Hub 1.10RedHatrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282*

Potential Mitigations

References