Common Weakness Enumeration

CWE-669

Allowed-with-Review

Incorrect Resource Transfer Between Spheres

Abstraction: Class · Status: Draft

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

188 vulnerabilities reference this CWE, most recent first.

GHSA-J3W4-VVQ3-QPF6

Vulnerability from github – Published: 2025-10-17 21:31 – Updated: 2025-10-18 03:30
VLAI
Details

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-62646"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-10-17T21:15:37Z",
    "severity": "MODERATE"
  },
  "details": "The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.",
  "id": "GHSA-j3w4-vvq3-qpf6",
  "modified": "2025-10-18T03:30:24Z",
  "published": "2025-10-17T21:31:19Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62646"
    },
    {
      "type": "WEB",
      "url": "https://archive.today/fMYQp"
    },
    {
      "type": "WEB",
      "url": "https://bobdahacker.com/blog/rbi-hacked-drive-thrus"
    },
    {
      "type": "WEB",
      "url": "https://web.archive.org/web/20250906134240/https:/bobdahacker.com/blog/rbi-hacked-drive-thrus"
    },
    {
      "type": "WEB",
      "url": "https://www.malwarebytes.com/blog/news/2025/09/popeyes-tim-hortons-burger-king-platforms-have-catastrophic-vulnerabilities-say-hackers"
    },
    {
      "type": "WEB",
      "url": "https://www.yahoo.com/news/articles/burger-king-hacked-attackers-impressed-124154038.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-J3WX-VG3Q-5R45

Vulnerability from github – Published: 2026-07-01 00:34 – Updated: 2026-07-01 15:35
VLAI
Details

Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-14151"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669",
      "CWE-693"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-06-30T23:17:26Z",
    "severity": "CRITICAL"
  },
  "details": "Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
  "id": "GHSA-j3wx-vg3q-5r45",
  "modified": "2026-07-01T15:35:10Z",
  "published": "2026-07-01T00:34:12Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14151"
    },
    {
      "type": "WEB",
      "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html"
    },
    {
      "type": "WEB",
      "url": "https://issues.chromium.org/issues/517381770"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-J45V-7HGC-XV9X

Vulnerability from github – Published: 2026-10-06 21:32 – Updated: 2026-10-06 21:32
VLAI
Details

In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-106555"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T21:17:19Z",
    "severity": "LOW"
  },
  "details": "In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.",
  "id": "GHSA-j45v-7hgc-xv9x",
  "modified": "2026-10-06T21:32:05Z",
  "published": "2026-10-06T21:32:05Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106555"
    },
    {
      "type": "WEB",
      "url": "https://www.openssh.org/releasenotes.html#10.6"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-J58V-28M8-49F3

Vulnerability from github – Published: 2026-08-11 21:33 – Updated: 2026-08-11 21:33
VLAI
Details

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-73281"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-08-11T20:18:49Z",
    "severity": "LOW"
  },
  "details": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
  "id": "GHSA-j58v-28m8-49f3",
  "modified": "2026-08-11T21:33:11Z",
  "published": "2026-08-11T21:33:11Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73281"
    },
    {
      "type": "WEB",
      "url": "https://www.openssh.org/releasenotes.html#10.5"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-J8CW-M86F-RXGW

Vulnerability from github – Published: 2022-05-24 19:03 – Updated: 2025-10-22 00:32
VLAI
Details

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-22900"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669",
      "CWE-94"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2021-05-27T12:15:00Z",
    "severity": "HIGH"
  },
  "details": "A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.",
  "id": "GHSA-j8cw-m86f-rxgw",
  "modified": "2025-10-22T00:32:13Z",
  "published": "2022-05-24T19:03:30Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22900"
    },
    {
      "type": "WEB",
      "url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22900"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-JF8Q-945G-9Q4C

Vulnerability from github – Published: 2026-10-01 15:42 – Updated: 2026-10-01 15:42
VLAI
Summary
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
Details

Summary

vm2 current head (v3.11.5, commit 7a1f5100b96f48d34e0fe104ab37c0acc5944f92) still exposes registered Node.js internal symbols from host WebStream prototypes to sandbox code.

The prior nodejs.* symbol hardening blocks Symbol.for('nodejs.<name>') at the source, but the extraction filters and bridge write traps still enumerate a fixed set of known registered symbols. On Node.js v25.8.0, stream/web exposes two additional registered symbols:

  • nodejs.stream.disturbed
  • nodejs.stream.errored

Sandbox code can extract those real host symbols with Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype) and then use them as write keys on host objects. On a real host ReadableStream, an attacker can make stream.Readable.isDisturbed(stream) return false after the stream has already been read.

Technical Details

lib/setup-sandbox.js correctly blocks future nodejs.* keys at the Symbol.for() source:

if (apply(localStringStartsWith, keyStr, ['nodejs.'])) {
  ...
  return fresh;
}

However, the extraction filters are still driven by a fixed realDangerousSymbols list. That list does not include nodejs.stream.disturbed or nodejs.stream.errored, so Object.getOwnPropertySymbols() and related paths can still return those real host symbols.

lib/bridge.js has the same fixed-list problem in isDangerousCrossRealmSymbol() and in the host-result scrub list. Because the two new symbols are not recognized, the set and defineProperty traps allow sandbox-originated writes using those keys.

Current-head source references:

  • lib/setup-sandbox.js:180-196 denies Symbol.for('nodejs.*') by namespace.
  • lib/setup-sandbox.js:214-230 uses a fixed realDangerousSymbols list for extraction filtering; the two reported symbols are absent.
  • lib/bridge.js:187-199 uses a fixed isDangerousCrossRealmSymbol() list; the two reported symbols are absent.
  • lib/bridge.js:1499-1509 treats the write trap as the last line of defense, but it only rejects keys recognized by that fixed list.

Impact

Sandbox code can corrupt host-visible WebStream state checks for host WebStream objects that cross into the sandbox. In the validated PoV, a stream that the host has already consumed is made to appear undisturbed to stream.Readable.isDisturbed().

This can bypass host logic that relies on Node's public stream-state helpers to enforce one-shot body consumption, reject errored streams, or decide whether a host WebStream is safe to hand to another component.

This is not a host-code-execution primitive in the current PoV. The report is an incomplete-fix / guard-coverage gap in the same symbol-boundary family as the prior nodejs.* symbol advisory.

Affected Package/Versions

Confirmed affected on Node.js v25.8.0:

  • v3.11.4
  • v3.11.5
  • current head 7a1f5100b96f48d34e0fe104ab37c0acc5944f92

v3.11.3 is also affected, but it predates the broader nodejs.* symbol fix. For this incomplete-fix report, the suggested affected range is >= 3.11.4, <= 3.11.5 on Node.js versions where these stream symbols exist.

No patched version is known.

Configuration Required

The PoV uses a VM where the embedder exposes a host WebStream object and the host stream/web module object to sandbox code:

const vm = new VM({ sandbox: { rs, streamWeb } });

This matches the same trust boundary as the earlier cross-realm symbol-write class: sandbox code must not be able to obtain registered Node.js internal symbols and write them back onto host objects.

The PoV is local-only. It does not require network access, a public target, NodeVM builtin access, process, filesystem access, or child-process access.

Local Proof of Concept

Run from the oss-zero-day-harness directory:

node submission-bundle/vm2-pov-test-incomplete-nodejs-stream-symbol-filter/pov-nodejs-stream-symbol-incomplete-fix.js

The PoV:

  1. The host creates a ReadableStream.
  2. The host reads one chunk so stream.Readable.isDisturbed(rs) is true.
  3. Sandbox code confirms Symbol.for('nodejs.stream.disturbed') is blocked and returns a sandbox-local symbol.
  4. Sandbox code extracts the real registered nodejs.stream.disturbed / nodejs.stream.errored symbols from the host ReadableStream.prototype.
  5. Sandbox code writes an own nodejs.stream.disturbed property onto the host stream with value false.
  6. The host calls stream.Readable.isDisturbed(rs) again and receives false.

Observed result on current head:

{
  "beforeHostDisturbed": true,
  "controls": {
    "symbolForDisturbedIsRegistered": false,
    "symbolForErroredIsRegistered": false
  },
  "extracted": [
    {
      "description": "nodejs.stream.disturbed",
      "keyFor": "nodejs.stream.disturbed"
    },
    {
      "description": "nodejs.stream.errored",
      "keyFor": "nodejs.stream.errored"
    }
  ],
  "overrideDisturbedOk": true,
  "afterHostDisturbed": false
}

Official Disclosure Policy Fit

vm2's SECURITY.md asks reporters not to create a public issue and to submit It asks for reproduction steps, affected versions, environment/configuration details, and potential impact:

  • Policy: https://github.com/patriksimek/vm2/blob/main/SECURITY.md
  • Private report route: https://github.com/patriksimek/vm2/security/advisories/new

This bundle is formatted for that private GitHub report flow and should not be posted publicly before maintainer triage and a fixed release.

Suggested Fix Direction

Make the dangerous-symbol checks namespace-based instead of list-based:

  • In setup-sandbox.js, make isDangerousSymbol(sym) return true for any registered symbol whose Symbol.keyFor(sym) starts with nodejs..
  • In bridge.js, make isDangerousCrossRealmSymbol(key) do the same for any symbol key crossing the bridge.
  • In host-result scrubbing, delete all own symbol keys whose registered key starts with nodejs. instead of iterating a hard-coded list.
  • Keep the current explicit list only as regression documentation, not as the complete security boundary.

Regression tests should include:

  • Object.getOwnPropertySymbols(ReadableStream.prototype) must not expose nodejs.stream.disturbed or nodejs.stream.errored.
  • A sandbox-local Symbol.for('nodejs.stream.disturbed') write must not affect host stream.Readable.isDisturbed().
  • Even if the real symbol is passed into the sandbox by a host test harness, set, defineProperty, and deleteProperty traps must reject writes and deletes against host objects.

Why This Is Not Intended Behavior

The hardening comments and tests establish the intended invariant:

  • any nodejs.* internal symbol should be sandbox-local when requested through Symbol.for();
  • dangerous registered symbols should not be enumerable/extractable from host objects;
  • even if a sandbox obtains one, bridge write traps should reject writes using that key.

This report shows that the source-side rule is active, but the extraction and write-trap rules are incomplete for newer registered nodejs.stream.* symbols.

Node's stream state helpers consult these symbols directly. For example, stream.Readable.isDisturbed() reads the internal disturbed symbol before falling back to public state. After sandbox writes an own property under the extracted symbol, the host helper returns attacker-controlled state.

Node's public documentation describes stream.isErrored(stream) as reporting whether a stream has encountered an error, and stream.Readable.isDisturbed(stream) as reporting whether the stream has been read from or cancelled:

  • https://nodejs.org/api/stream.html#streamiserroredstream
  • https://nodejs.org/api/stream.html#streamreadableisdisturbedstream
Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 3.11.6"
      },
      "package": {
        "ecosystem": "npm",
        "name": "vm2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.11.4"
            },
            {
              "fixed": "3.11.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-92952"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-01T15:42:15Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "## Summary\n\nvm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) still exposes registered Node.js internal symbols from host WebStream prototypes to sandbox code.\n\nThe prior `nodejs.*` symbol hardening blocks `Symbol.for(\u0027nodejs.\u003cname\u003e\u0027)` at the source, but the extraction filters and bridge write traps still enumerate a fixed set of known registered symbols. On Node.js `v25.8.0`, `stream/web` exposes two additional registered symbols:\n\n- `nodejs.stream.disturbed`\n- `nodejs.stream.errored`\n\nSandbox code can extract those real host symbols with `Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype)` and then use them as write keys on host objects. On a real host `ReadableStream`, an attacker can make `stream.Readable.isDisturbed(stream)` return `false` after the stream has already been read.\n\n## Technical Details\n\n`lib/setup-sandbox.js` correctly blocks future `nodejs.*` keys at the `Symbol.for()` source:\n\n```js\nif (apply(localStringStartsWith, keyStr, [\u0027nodejs.\u0027])) {\n  ...\n  return fresh;\n}\n```\n\nHowever, the extraction filters are still driven by a fixed `realDangerousSymbols` list. That list does not include `nodejs.stream.disturbed` or `nodejs.stream.errored`, so `Object.getOwnPropertySymbols()` and related paths can still return those real host symbols.\n\n`lib/bridge.js` has the same fixed-list problem in `isDangerousCrossRealmSymbol()` and in the host-result scrub list. Because the two new symbols are not recognized, the `set` and `defineProperty` traps allow sandbox-originated writes using those keys.\n\nCurrent-head source references:\n\n- `lib/setup-sandbox.js:180-196` denies `Symbol.for(\u0027nodejs.*\u0027)` by namespace.\n- `lib/setup-sandbox.js:214-230` uses a fixed `realDangerousSymbols` list for extraction filtering; the two reported symbols are absent.\n- `lib/bridge.js:187-199` uses a fixed `isDangerousCrossRealmSymbol()` list; the two reported symbols are absent.\n- `lib/bridge.js:1499-1509` treats the write trap as the last line of defense, but it only rejects keys recognized by that fixed list.\n\n## Impact\n\nSandbox code can corrupt host-visible WebStream state checks for host WebStream objects that cross into the sandbox. In the validated PoV, a stream that the host has already consumed is made to appear undisturbed to `stream.Readable.isDisturbed()`.\n\nThis can bypass host logic that relies on Node\u0027s public stream-state helpers to enforce one-shot body consumption, reject errored streams, or decide whether a host WebStream is safe to hand to another component.\n\nThis is not a host-code-execution primitive in the current PoV. The report is an incomplete-fix / guard-coverage gap in the same symbol-boundary family as the prior `nodejs.*` symbol advisory.\n\n## Affected Package/Versions\n\nConfirmed affected on Node.js `v25.8.0`:\n\n- `v3.11.4`\n- `v3.11.5`\n- current head `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`\n\n`v3.11.3` is also affected, but it predates the broader `nodejs.*` symbol fix. For this incomplete-fix report, the suggested affected range is `\u003e= 3.11.4, \u003c= 3.11.5` on Node.js versions where these stream symbols exist.\n\nNo patched version is known.\n\n## Configuration Required\n\nThe PoV uses a `VM` where the embedder exposes a host WebStream object and the host `stream/web` module object to sandbox code:\n\n```js\nconst vm = new VM({ sandbox: { rs, streamWeb } });\n```\n\nThis matches the same trust boundary as the earlier cross-realm symbol-write class: sandbox code must not be able to obtain registered Node.js internal symbols and write them back onto host objects.\n\nThe PoV is local-only. It does not require network access, a public target, `NodeVM` builtin access, `process`, filesystem access, or child-process access.\n\n## Local Proof of Concept\n\nRun from the `oss-zero-day-harness` directory:\n\n```sh\nnode submission-bundle/vm2-pov-test-incomplete-nodejs-stream-symbol-filter/pov-nodejs-stream-symbol-incomplete-fix.js\n```\n\nThe PoV:\n\n1. The host creates a `ReadableStream`.\n2. The host reads one chunk so `stream.Readable.isDisturbed(rs)` is `true`.\n3. Sandbox code confirms `Symbol.for(\u0027nodejs.stream.disturbed\u0027)` is blocked and returns a sandbox-local symbol.\n4. Sandbox code extracts the real registered `nodejs.stream.disturbed` / `nodejs.stream.errored` symbols from the host `ReadableStream.prototype`.\n5. Sandbox code writes an own `nodejs.stream.disturbed` property onto the host stream with value `false`.\n6. The host calls `stream.Readable.isDisturbed(rs)` again and receives `false`.\n\nObserved result on current head:\n\n```json\n{\n  \"beforeHostDisturbed\": true,\n  \"controls\": {\n    \"symbolForDisturbedIsRegistered\": false,\n    \"symbolForErroredIsRegistered\": false\n  },\n  \"extracted\": [\n    {\n      \"description\": \"nodejs.stream.disturbed\",\n      \"keyFor\": \"nodejs.stream.disturbed\"\n    },\n    {\n      \"description\": \"nodejs.stream.errored\",\n      \"keyFor\": \"nodejs.stream.errored\"\n    }\n  ],\n  \"overrideDisturbedOk\": true,\n  \"afterHostDisturbed\": false\n}\n```\n\n## Official Disclosure Policy Fit\n\nvm2\u0027s `SECURITY.md` asks reporters not to create a public issue and to submit It asks for reproduction steps, affected versions, environment/configuration details, and potential impact:\n\n- Policy: https://github.com/patriksimek/vm2/blob/main/SECURITY.md\n- Private report route: https://github.com/patriksimek/vm2/security/advisories/new\n\nThis bundle is formatted for that private GitHub report flow and should not be posted publicly before maintainer triage and a fixed release.\n\n## Suggested Fix Direction\n\nMake the dangerous-symbol checks namespace-based instead of list-based:\n\n- In `setup-sandbox.js`, make `isDangerousSymbol(sym)` return true for any registered symbol whose `Symbol.keyFor(sym)` starts with `nodejs.`.\n- In `bridge.js`, make `isDangerousCrossRealmSymbol(key)` do the same for any symbol key crossing the bridge.\n- In host-result scrubbing, delete all own symbol keys whose registered key starts with `nodejs.` instead of iterating a hard-coded list.\n- Keep the current explicit list only as regression documentation, not as the complete security boundary.\n\nRegression tests should include:\n\n- `Object.getOwnPropertySymbols(ReadableStream.prototype)` must not expose `nodejs.stream.disturbed` or `nodejs.stream.errored`.\n- A sandbox-local `Symbol.for(\u0027nodejs.stream.disturbed\u0027)` write must not affect host `stream.Readable.isDisturbed()`.\n- Even if the real symbol is passed into the sandbox by a host test harness, `set`, `defineProperty`, and `deleteProperty` traps must reject writes and deletes against host objects.\n\n## Why This Is Not Intended Behavior\n\nThe hardening comments and tests establish the intended invariant:\n\n- any `nodejs.*` internal symbol should be sandbox-local when requested through `Symbol.for()`;\n- dangerous registered symbols should not be enumerable/extractable from host objects;\n- even if a sandbox obtains one, bridge write traps should reject writes using that key.\n\nThis report shows that the source-side rule is active, but the extraction and write-trap rules are incomplete for newer registered `nodejs.stream.*` symbols.\n\nNode\u0027s stream state helpers consult these symbols directly. For example, `stream.Readable.isDisturbed()` reads the internal disturbed symbol before falling back to public state. After sandbox writes an own property under the extracted symbol, the host helper returns attacker-controlled state.\n\nNode\u0027s public documentation describes `stream.isErrored(stream)` as reporting whether a stream has encountered an error, and `stream.Readable.isDisturbed(stream)` as reporting whether the stream has been read from or cancelled:\n\n- https://nodejs.org/api/stream.html#streamiserroredstream\n- https://nodejs.org/api/stream.html#streamreadableisdisturbedstream",
  "id": "GHSA-jf8q-945g-9q4c",
  "modified": "2026-10-01T15:42:15Z",
  "published": "2026-10-01T15:42:15Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-jf8q-945g-9q4c"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92952"
    },
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/commit/a45444d5abbdfa59055528f584df5f21cc7c42da"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/patriksimek/vm2"
    },
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/releases/tag/v3.11.7"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/vm2-3.11.4-through-3.11.6-sandbox-symbol-filtering-bypass"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks"
}

GHSA-JRGH-F66H-M27J

Vulnerability from github – Published: 2022-05-24 16:54 – Updated: 2023-04-26 21:30
VLAI
Details

D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2019-13263"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2019-08-27T18:15:00Z",
    "severity": "HIGH"
  },
  "details": "D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.",
  "id": "GHSA-jrgh-f66h-m27j",
  "modified": "2023-04-26T21:30:29Z",
  "published": "2022-05-24T16:54:55Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13263"
    },
    {
      "type": "WEB",
      "url": "https://orenlab.sise.bgu.ac.il/publications/CrossRouter"
    },
    {
      "type": "WEB",
      "url": "https://www.usenix.org/system/files/woot19-paper_ovadia.pdf"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-JRH2-F5JC-XPGR

Vulnerability from github – Published: 2026-06-04 00:30 – Updated: 2026-07-14 19:35
VLAI
Summary
OpenStack Ironic allows Boot Script Injection
Details

OpenStack Ironic through 35.0.x allows Boot Script Injection.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "ironic"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "17.0.0"
            },
            {
              "fixed": "26.1.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "ironic"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "27.0.0"
            },
            {
              "fixed": "29.0.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "ironic"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "30.0.0"
            },
            {
              "fixed": "32.0.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "ironic"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "33.0.0"
            },
            {
              "fixed": "35.0.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-46447"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-14T19:35:21Z",
    "nvd_published_at": "2026-06-03T22:16:34Z",
    "severity": "MODERATE"
  },
  "details": "OpenStack Ironic through 35.0.x allows Boot Script Injection.",
  "id": "GHSA-jrh2-f5jc-xpgr",
  "modified": "2026-07-14T19:35:21Z",
  "published": "2026-06-04T00:30:25Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46447"
    },
    {
      "type": "WEB",
      "url": "https://bugs.launchpad.net/ironic/+bug/2150624"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/openstack/ironic"
    },
    {
      "type": "WEB",
      "url": "https://security.openstack.org/ossa/OSSA-2026-017.html"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/06/03/11"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/06/15/9"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "OpenStack Ironic allows Boot Script Injection"
}

GHSA-JWH6-MWXG-X75J

Vulnerability from github – Published: 2022-05-24 16:54 – Updated: 2024-04-04 01:44
VLAI
Details

Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from the server every time the user visits the D, creating business confusion. In the worst case, all available resources are consumed while processing the data, resulting in unavailability of the service to legitimate users. This occurs because non-editable parameters can be modified by manually editing a disabled form field within the developer options.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2018-17791"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2019-08-21T20:15:00Z",
    "severity": "HIGH"
  },
  "details": "Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an \"improper server side validation\" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from the server every time the user visits the D, creating business confusion. In the worst case, all available resources are consumed while processing the data, resulting in unavailability of the service to legitimate users. This occurs because non-editable parameters can be modified by manually editing a disabled form field within the developer options.",
  "id": "GHSA-jwh6-mwxg-x75j",
  "modified": "2024-04-04T01:44:23Z",
  "published": "2022-05-24T16:54:20Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-17791"
    },
    {
      "type": "WEB",
      "url": "https://packetstormsecurity.com/files/cve/CVE-2018-17791"
    },
    {
      "type": "WEB",
      "url": "http://packetstormsecurity.com/files/154061/OmniDoc-7.0-Input-Validation.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-JWVX-8MRF-4V7M

Vulnerability from github – Published: 2025-09-30 18:30 – Updated: 2025-09-30 18:30
VLAI
Details

The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-56675"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-669"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-09-30T18:15:50Z",
    "severity": "LOW"
  },
  "details": "The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.",
  "id": "GHSA-jwvx-8mrf-4v7m",
  "modified": "2025-09-30T18:30:25Z",
  "published": "2025-09-30T18:30:25Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-56675"
    },
    {
      "type": "WEB",
      "url": "https://httpscolonforwardslashforwardslashwwwdotzoltanbalazsdotcom.com/2025/07/15/eken-wifi-leak.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.