<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T20:10:43.317696+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03752</id>
    <title>bdu:2023-03752</title>
    <updated>2026-10-06T20:10:43.328412+00:00</updated>
    <content>bdu:2023-03752</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529</id>
    <title>certfr-2024-avi-0529 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-06T20:10:43.328458+00:00</updated>
    <content>certfr-2024-avi-0529</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264923</id>
    <title>EUVD-2026-264923</title>
    <updated>2026-10-06T20:10:43.328478+00:00</updated>
    <content>EUVD-2026-264923</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37466</id>
    <title>fkie_cve-2023-37466</title>
    <updated>2026-10-06T20:10:43.328491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with the `@@species` accessor property allowing attackers to escape the sandbox and run arbitrary code, potentially allowing remote code execution inside the context of vm2 sandbox. Version 3.10.0 contains a patch for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-37466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cchq-frgv-rjh5</id>
    <title>GHSA-cchq-frgv-rjh5 — vm2 Sandbox Escape vulnerability</title>
    <updated>2026-10-06T20:10:43.328523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed, allowing attackers to escape the sandbox and run arbitrary code.</p>
<p>### Impact
Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.</p>
<p>### Patches
None.</p>
<p>### Workarounds
None.</p>
<p>### References
PoC - https://gist.github.com/leesh3288/f693061e6523c97274ad5298eb2c74e9</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>- Open an issue in [VM2](https://github.com/patriksimek/vm2)</p>
<p>Thanks to [Xion](https://twitter.com/0x10n) (SeungHyun Lee) of [KAIST Hacking Lab](https://kaist-hacking.github.io/) for disclosing this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cchq-frgv-rjh5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-37466</id>
    <title>gsd-2023-37466</title>
    <updated>2026-10-06T20:10:43.328556+00:00</updated>
    <content>gsd-2023-37466</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-37466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:4972</id>
    <title>RHSA-2023:4972 — Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.1.8 security updates and bug fixes</title>
    <updated>2026-10-06T20:10:43.328568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openshift: OCP &amp; FIPS mode vm2: Promise handler sanitization can be bypassed allowing attackers to escape the sandbox and run arbitrary code vm2: custom inspect function allows attackers to escape the sandbox and run arbitrary code</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:4972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1752</id>
    <title>WID-SEC-W-2023-1752 — vm2: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-06T20:10:43.328592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vm2 ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1752"/>
  </entry>
</feed>
