Common Weakness Enumeration

CWE-114

Discouraged

Process Control

Abstraction: Class · Status: Incomplete

Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.

40 vulnerabilities reference this CWE, most recent first.

CVE-2019-8458 (GCVE-0-2019-8458)

Vulnerability from cvelistv5 – Published: 2019-06-20 16:44 – Updated: 2024-08-04 21:17
VLAI
Summary
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.
Severity
No CVSS data available.
CWE
References
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T21:17:31.415Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Check Point Endpoint Security Client for Windows, Anti-Malware blade",
          "vendor": "Check Point",
          "versions": [
            {
              "status": "affected",
              "version": "before E81.00"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-114",
              "description": "CWE-114",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2019-06-20T16:44:33.000Z",
        "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "shortName": "checkpoint"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cve@checkpoint.com",
          "ID": "CVE-2019-8458",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Check Point Endpoint Security Client for Windows, Anti-Malware blade",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "before E81.00"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Check Point"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-114"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053",
              "refsource": "CONFIRM",
              "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
    "assignerShortName": "checkpoint",
    "cveId": "CVE-2019-8458",
    "datePublished": "2019-06-20T16:44:33.000Z",
    "dateReserved": "2019-02-18T00:00:00.000Z",
    "dateUpdated": "2024-08-04T21:17:31.415Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2019-8453 (GCVE-0-2019-8453)

Vulnerability from cvelistv5 – Published: 2019-04-17 14:06 – Updated: 2024-08-04 21:17
VLAI
Summary
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.
Severity
No CVSS data available.
CWE
References
Impacted products
Vendor Product Version
n/a Check Point ZoneAlarm Affected: up to 15.4.062
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T21:17:31.426Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960"
          },
          {
            "name": "108029",
            "tags": [
              "vdb-entry",
              "x_refsource_BID",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/108029"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Check Point ZoneAlarm",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "up to 15.4.062"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-114",
              "description": "CWE-114",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2019-04-23T15:06:11.000Z",
        "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "shortName": "checkpoint"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960"
        },
        {
          "name": "108029",
          "tags": [
            "vdb-entry",
            "x_refsource_BID"
          ],
          "url": "http://www.securityfocus.com/bid/108029"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cve@checkpoint.com",
          "ID": "CVE-2019-8453",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Check Point ZoneAlarm",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "up to 15.4.062"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "n/a"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-114"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960",
              "refsource": "MISC",
              "url": "https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960"
            },
            {
              "name": "108029",
              "refsource": "BID",
              "url": "http://www.securityfocus.com/bid/108029"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
    "assignerShortName": "checkpoint",
    "cveId": "CVE-2019-8453",
    "datePublished": "2019-04-17T14:06:40.000Z",
    "dateReserved": "2019-02-18T00:00:00.000Z",
    "dateUpdated": "2024-08-04T21:17:31.426Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

GHSA-3JPM-WF77-VWQX

Vulnerability from github – Published: 2026-03-18 18:31 – Updated: 2026-03-18 18:31
VLAI
Details

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to code execution.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-26945"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-114"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-03-18T18:16:26Z",
    "severity": "MODERATE"
  },
  "details": "Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability.  A high privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to code execution.",
  "id": "GHSA-3jpm-wf77-vwqx",
  "modified": "2026-03-18T18:31:18Z",
  "published": "2026-03-18T18:31:18Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26945"
    },
    {
      "type": "WEB",
      "url": "https://www.dell.com/support/kbdoc/en-us/000434533/dsa-2026-113-security-update-for-dell-idrac9-and-idrac10-vulnerabilities"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-46PR-C5WC-XFFX

Vulnerability from github – Published: 2026-10-01 15:28 – Updated: 2026-10-01 15:28
VLAI
Summary
vm2 crypto builtin loads attacker native code through setEngine
Details

Summary

vm2 3.11.6 exposes the host crypto module to a NodeVM when that single builtin is allowed. The module is presented through a read-only bridge, but its functions still execute with host-process authority. crypto.setEngine() accepts a filesystem path and asks OpenSSL to dynamically load the referenced native library.

An attacker whose untrusted plugin package contains a native library can therefore load that library into the host process by calling crypto.setEngine() from sandboxed JavaScript. The native library's constructor executes before OpenSSL finishes validating whether the file is a usable engine. Consequently, even the expected ERR_CRYPTO_ENGINE_UNKNOWN exception occurs only after arbitrary native code has already run.

The exploit requires only the crypto builtin. It does not require fs, process, module, child_process, worker_threads, vm, inspector, unrestricted builtins, or vm2 nesting.

Details

The vulnerable boundary is the generic builtin loader. Builtins that are not specially wrapped or classified as dangerous are imported in the host realm and exposed through a recursive read-only proxy:

builtins.set(key, special ? special : vm => vm.readonly(hostRequire(key)));

Read-only prevents sandbox code from assigning properties on the module object. It does not reduce the authority of callable exports. Calls are forwarded to the original host function with bridge values converted back to host values.

The crypto module includes this callable export:

crypto.setEngine(enginePath)

When enginePath names a dynamic library, OpenSSL loads that file into the current process. Operating-system dynamic loaders execute library constructors as part of loading. Engine-symbol validation happens afterward. A file does not have to become a functional cryptographic engine for its constructor to execute.

The resulting exploit flow is:

attacker supplies an untrusted plugin package containing a native library
  -> host executes the plugin in NodeVM with only crypto allowed
  -> plugin calls crypto.setEngine(pathToBundledLibrary)
  -> vm2 forwards the call to the host crypto module
  -> OpenSSL asks the operating-system loader to load the library
  -> the library constructor executes native code in the host process
  -> OpenSSL may then reject the file, but host compromise has already occurred

This is different from merely granting JavaScript filesystem access. A plugin system commonly has to place an untrusted package on disk before running its JavaScript. The native file can therefore already exist inside that package even when the sandbox denies fs and all process-execution builtins. Allowing crypto for hashing or signature verification unexpectedly turns that inert package file into a native-code execution primitive.

PoC

The attached PoC is local and harmless. Its native library constructor creates a marker file; it does not spawn a process, open a network connection, or modify any other file.

  1. Install Node.js with OpenSSL engine support, a C compiler, and npm.
  2. In the attached poc directory, install the exact affected package:

bash npm install --ignore-scripts

  1. Build the marker library.

On macOS:

bash cc -dynamiclib -O2 -o probe-engine.dylib engine_probe.c node poc.js ./probe-engine.dylib

On Linux:

bash cc -shared -fPIC -O2 -o probe-engine.so engine_probe.c node poc.js ./probe-engine.so

  1. A vulnerable result contains all of the following:

  2. the sandbox configuration lists only crypto as an allowed builtin;

  3. crypto.setEngine() reports ERR_CRYPTO_ENGINE_UNKNOWN or returns;
  4. vm2-setengine-native-marker.txt exists afterward;
  5. the marker contains VM2_SETENGINE_NATIVE_CODE_EXECUTED.

The exception is not a negative result. The marker proves that the native constructor ran before engine validation failed.

Impact

This is a sandbox escape to arbitrary native code execution. The code runs with the operating-system identity and privileges of the Node.js host process, outside all vm2 language and module restrictions.

An attacker can replace the marker-only constructor with native code that:

  • reads application secrets, environment variables, credentials, and files available to the host user;
  • modifies application data or executable files and establishes persistence;
  • accesses internal services using the host's network identity;
  • steals other tenants' data from the same process;
  • terminates or corrupts the host process; and
  • executes arbitrary operating-system actions permitted to the host account.

The realistic affected workflow is a plugin, automation, notebook, or multi-tenant code runner that stores attacker-supplied package contents on disk and runs the package's JavaScript in NodeVM while allowing crypto. The attacker does not need the sandbox to expose a file-write or command-execution module.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 3.11.6"
      },
      "package": {
        "ecosystem": "npm",
        "name": "vm2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.11.3"
            },
            {
              "fixed": "3.11.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-92939"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-114"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-01T15:28:36Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
  },
  "details": "Summary\n\nvm2 3.11.6 exposes the host `crypto` module to a `NodeVM` when that single builtin is allowed. The module is presented through a read-only bridge, but its functions still execute with host-process authority. `crypto.setEngine()` accepts a filesystem path and asks OpenSSL to dynamically load the referenced native library.\n\nAn attacker whose untrusted plugin package contains a native library can therefore load that library into the host process by calling `crypto.setEngine()` from sandboxed JavaScript. The native library\u0027s constructor executes before OpenSSL finishes validating whether the file is a usable engine. Consequently, even the expected `ERR_CRYPTO_ENGINE_UNKNOWN` exception occurs only after arbitrary native code has already run.\n\nThe exploit requires only the `crypto` builtin. It does not require `fs`, `process`, `module`, `child_process`, `worker_threads`, `vm`, `inspector`, unrestricted builtins, or vm2 nesting.\n\n### Details\n\nThe vulnerable boundary is the generic builtin loader. Builtins that are not specially wrapped or classified as dangerous are imported in the host realm and exposed through a recursive read-only proxy:\n\n```js\nbuiltins.set(key, special ? special : vm =\u003e vm.readonly(hostRequire(key)));\n```\n\nRead-only prevents sandbox code from assigning properties on the module object. It does not reduce the authority of callable exports. Calls are forwarded to the original host function with bridge values converted back to host values.\n\nThe `crypto` module includes this callable export:\n\n```js\ncrypto.setEngine(enginePath)\n```\n\nWhen `enginePath` names a dynamic library, OpenSSL loads that file into the current process. Operating-system dynamic loaders execute library constructors as part of loading. Engine-symbol validation happens afterward. A file does not have to become a functional cryptographic engine for its constructor to execute.\n\nThe resulting exploit flow is:\n\n```text\nattacker supplies an untrusted plugin package containing a native library\n  -\u003e host executes the plugin in NodeVM with only crypto allowed\n  -\u003e plugin calls crypto.setEngine(pathToBundledLibrary)\n  -\u003e vm2 forwards the call to the host crypto module\n  -\u003e OpenSSL asks the operating-system loader to load the library\n  -\u003e the library constructor executes native code in the host process\n  -\u003e OpenSSL may then reject the file, but host compromise has already occurred\n```\n\nThis is different from merely granting JavaScript filesystem access. A plugin system commonly has to place an untrusted package on disk before running its JavaScript. The native file can therefore already exist inside that package even when the sandbox denies `fs` and all process-execution builtins. Allowing `crypto` for hashing or signature verification unexpectedly turns that inert package file into a native-code execution primitive.\n\n### PoC\n\nThe attached PoC is local and harmless. Its native library constructor creates a marker file; it does not spawn a process, open a network connection, or modify any other file.\n\n1. Install Node.js with OpenSSL engine support, a C compiler, and npm.\n2. In the attached `poc` directory, install the exact affected package:\n\n   ```bash\n   npm install --ignore-scripts\n   ```\n\n3. Build the marker library.\n\n   On macOS:\n\n   ```bash\n   cc -dynamiclib -O2 -o probe-engine.dylib engine_probe.c\n   node poc.js ./probe-engine.dylib\n   ```\n\n   On Linux:\n\n   ```bash\n   cc -shared -fPIC -O2 -o probe-engine.so engine_probe.c\n   node poc.js ./probe-engine.so\n   ```\n\n4. A vulnerable result contains all of the following:\n\n   - the sandbox configuration lists only `crypto` as an allowed builtin;\n   - `crypto.setEngine()` reports `ERR_CRYPTO_ENGINE_UNKNOWN` or returns;\n   - `vm2-setengine-native-marker.txt` exists afterward;\n   - the marker contains `VM2_SETENGINE_NATIVE_CODE_EXECUTED`.\n\nThe exception is not a negative result. The marker proves that the native constructor ran before engine validation failed.\n\n### Impact\n\nThis is a sandbox escape to arbitrary native code execution. The code runs with the operating-system identity and privileges of the Node.js host process, outside all vm2 language and module restrictions.\n\nAn attacker can replace the marker-only constructor with native code that:\n\n- reads application secrets, environment variables, credentials, and files available to the host user;\n- modifies application data or executable files and establishes persistence;\n- accesses internal services using the host\u0027s network identity;\n- steals other tenants\u0027 data from the same process;\n- terminates or corrupts the host process; and\n- executes arbitrary operating-system actions permitted to the host account.\n\nThe realistic affected workflow is a plugin, automation, notebook, or multi-tenant code runner that stores attacker-supplied package contents on disk and runs the package\u0027s JavaScript in `NodeVM` while allowing `crypto`. The attacker does not need the sandbox to expose a file-write or command-execution module.",
  "id": "GHSA-46pr-c5wc-xffx",
  "modified": "2026-10-01T15:28:36Z",
  "published": "2026-10-01T15:28:36Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-46pr-c5wc-xffx"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92939"
    },
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483daa"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/patriksimek/vm2"
    },
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/releases/tag/v3.11.7"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-native-code-execution-via-crypto-setengine"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "vm2 crypto builtin loads attacker native code through setEngine"
}

GHSA-52JJ-6W68-3M25

Vulnerability from github – Published: 2024-08-27 12:30 – Updated: 2025-05-17 00:30
VLAI
Details

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended actor-controlled shared libraries when the server binary is started, potentially resulting in the unintended actor gaining full control over the MongoDB server process. This issue affects MongoDB Server v5.0 versions prior to 5.0.14 and MongoDB Server v6.0 versions prior to 6.0.3.

Required Configuration: Only environments with Linux as the underlying operating system is affected by this issue

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-8207"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-114",
      "CWE-610"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-08-27T12:15:04Z",
    "severity": "MODERATE"
  },
  "details": "In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended actor-controlled shared libraries when the server binary is started, potentially resulting in the unintended actor gaining full control over the MongoDB server process. This issue affects MongoDB Server v5.0 versions prior to 5.0.14 and MongoDB Server v6.0 versions prior to 6.0.3.\n\nRequired Configuration: Only environments with Linux as the underlying operating system is affected by this issue",
  "id": "GHSA-52jj-6w68-3m25",
  "modified": "2025-05-17T00:30:25Z",
  "published": "2024-08-27T12:30:44Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8207"
    },
    {
      "type": "WEB",
      "url": "https://jira.mongodb.org/browse/SERVER-69507"
    },
    {
      "type": "WEB",
      "url": "https://security.netapp.com/advisory/ntap-20250516-0009"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-67G9-M5C8-562G

Vulnerability from github – Published: 2025-03-18 18:30 – Updated: 2025-03-18 18:30
VLAI
Details

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-56347"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-114"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-03-18T17:15:44Z",
    "severity": "CRITICAL"
  },
  "details": "IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.",
  "id": "GHSA-67g9-m5c8-562g",
  "modified": "2025-03-18T18:30:49Z",
  "published": "2025-03-18T18:30:49Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56347"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7186621"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-68FX-M736-WFWF

Vulnerability from github – Published: 2025-03-18 18:30 – Updated: 2025-03-18 18:30
VLAI
Details

IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-56346"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-114"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-03-18T17:15:44Z",
    "severity": "CRITICAL"
  },
  "details": "IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.",
  "id": "GHSA-68fx-m736-wfwf",
  "modified": "2025-03-18T18:30:49Z",
  "published": "2025-03-18T18:30:49Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56346"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7186621"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-69VM-8RMF-JW2P

Vulnerability from github – Published: 2025-02-28 21:32 – Updated: 2025-02-28 21:32
VLAI
Details

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-0160"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-114"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-02-28T19:15:36Z",
    "severity": "HIGH"
  },
  "details": "IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1)  could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.",
  "id": "GHSA-69vm-8rmf-jw2p",
  "modified": "2025-02-28T21:32:20Z",
  "published": "2025-02-28T21:32:20Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0160"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7184182"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6JGM-4W45-VH8J

Vulnerability from github – Published: 2026-09-17 15:32 – Updated: 2026-10-01 15:28
Withdrawn 2026-10-01 VLAI
Summary
Duplicate Advisory: vm2 crypto builtin loads attacker native code through setEngine
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-46pr-c5wc-xffx. This link is maintained to preserve external references.

Original Description

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an untrusted plugin package already written to disk); OpenSSL asks the operating-system dynamic loader to load the file, and the library's constructor executes native code in the host process before engine-symbol validation rejects it. Exploitation requires only the crypto builtin and does not require fs, process, module, child_process, worker_threads, vm, or inspector access, resulting in a sandbox escape and arbitrary native code execution. Fixed in 3.11.7.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "vm2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.11.3"
            },
            {
              "last_affected": "3.11.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-114"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-01T15:28:21Z",
    "nvd_published_at": "2026-09-17T14:17:58Z",
    "severity": "CRITICAL"
  },
  "details": "## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of\u00a0GHSA-46pr-c5wc-xffx. This link is maintained to preserve external references.\n\n## Original Description\nvm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an untrusted plugin package already written to disk); OpenSSL asks the operating-system dynamic loader to load the file, and the library\u0027s constructor executes native code in the host process before engine-symbol validation rejects it. Exploitation requires only the crypto builtin and does not require fs, process, module, child_process, worker_threads, vm, or inspector access, resulting in a sandbox escape and arbitrary native code execution. Fixed in 3.11.7.",
  "id": "GHSA-6jgm-4w45-vh8j",
  "modified": "2026-10-01T15:28:21Z",
  "published": "2026-09-17T15:32:14Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-46pr-c5wc-xffx"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92939"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-native-code-execution-via-crypto-setengine"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Duplicate Advisory: vm2 crypto builtin loads attacker native code through setEngine",
  "withdrawn": "2026-10-01T15:28:21Z"
}

GHSA-892W-Q9HR-HM9C

Vulnerability from github – Published: 2023-10-05 00:30 – Updated: 2024-04-04 08:18
VLAI
Details

Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-40299"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-114"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-10-04T22:15:09Z",
    "severity": "HIGH"
  },
  "details": "Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.",
  "id": "GHSA-892w-q9hr-hm9c",
  "modified": "2024-04-04T08:18:50Z",
  "published": "2023-10-05T00:30:14Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40299"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Kong/insomnia/pull/6217/commits"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Kong/insomnia/releases"
    },
    {
      "type": "WEB",
      "url": "https://insomnia.rest/changelog"
    },
    {
      "type": "WEB",
      "url": "https://www.angelystor.com/posts/cve-2023-40299"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

Mitigation
Architecture and Design

Strategy: Libraries or Frameworks

Libraries that are loaded should be well understood and come from a trusted source. The application can execute code contained in the native libraries, which often contain calls that are susceptible to other security problems, such as buffer overflows or command injection. All native libraries should be validated to determine if the application requires the use of the library. It is very difficult to determine what these native libraries actually do, and the potential for malicious code is high. In addition, the potential for an inadvertent mistake in these native libraries is also high, as many are written in C or C++ and may be susceptible to buffer overflow or race condition problems. To help prevent buffer overflow attacks, validate all input to native calls for content and length. If the native library does not come from a trusted source, review the source code of the library. The library should be built from the reviewed source before using it.

CAPEC-108: Command Line Execution through SQL Injection

An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Sometime later, an unscrupulous backend application (or could be part of the functionality of the same application) fetches the injected data stored in the database and uses this data as command line arguments without performing proper validation. The malicious data escapes that data plane by spawning new commands to be executed on the host.

CAPEC-640: Inclusion of Code in Existing Process

The adversary takes advantage of a bug in an application failing to verify the integrity of the running process to execute arbitrary code in the address space of a separate live process. The adversary could use running code in the context of another process to try to access process's memory, system/network resources, etc. The goal of this attack is to evade detection defenses and escalate privileges by masking the malicious code under an existing legitimate process. Examples of approaches include but not limited to: dynamic-link library (DLL) injection, portable executable injection, thread execution hijacking, ptrace system calls, VDSO hijacking, function hooking, reflective code loading, and more.