vm2 Buffer Alloc Limit Bypass via Buffer.concat and Buffer.from
A vulnerability in vm2 allows untrusted sandbox code to bypass the bufferAllocLimit cap, leading to a potential DoS attack. The vulnerability has a CVSS score of 8.7 and is identified as CVE-2026-47683.