<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:36:12.904982+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03966</id>
    <title>bdu:2023-03966</title>
    <updated>2026-10-06T18:36:12.925565+00:00</updated>
    <content>bdu:2023-03966</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529</id>
    <title>certfr-2024-avi-0529 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-06T18:36:12.925608+00:00</updated>
    <content>certfr-2024-avi-0529</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258441</id>
    <title>EUVD-2026-258441</title>
    <updated>2026-10-06T18:36:12.925627+00:00</updated>
    <content>EUVD-2026-258441</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258441"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37903</id>
    <title>fkie_cve-2023-37903</title>
    <updated>2026-10-06T18:36:12.925638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-37903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g644-9gfx-q4q4</id>
    <title>GHSA-g644-9gfx-q4q4 — vm2 Sandbox Escape vulnerability</title>
    <updated>2026-10-06T18:36:12.925668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>In vm2 for versions up to 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code.</p>
<p>### Impact
Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.</p>
<p>### Patches
None.</p>
<p>### Workarounds
None.</p>
<p>### References
PoC is to be disclosed on or after the 5th of September.</p>
<p>### Similarity with [CVE-2023-37466](https://nvd.nist.gov/vuln/detail/CVE-2023-37466)
While this advisory might look similar to [CVE-2023-37466](https://nvd.nist.gov/vuln/detail/CVE-2023-37466), it is a completely different way of escaping the sandbox.</p>
<p>### For more information
If you have any questions or comments about this advisory:</p>
<p>- Open an issue in [VM2](https://github.com/patriksimek/vm2)</p>
<p>Thanks to [Xion](https://twitter.com/0x10n) (SeungHyun Lee) of [KAIST Hacking Lab](https://kaist-hacking.github.io/) for disclosing this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g644-9gfx-q4q4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-37903</id>
    <title>gsd-2023-37903</title>
    <updated>2026-10-06T18:36:12.925700+00:00</updated>
    <content>gsd-2023-37903</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-37903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:4972</id>
    <title>RHSA-2023:4972 — Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.1.8 security updates and bug fixes</title>
    <updated>2026-10-06T18:36:12.925711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openshift: OCP &amp; FIPS mode vm2: Promise handler sanitization can be bypassed allowing attackers to escape the sandbox and run arbitrary code vm2: custom inspect function allows attackers to escape the sandbox and run arbitrary code</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:4972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1863</id>
    <title>WID-SEC-W-2023-1863 — vm2: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-06T18:36:12.925740+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vm2 ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1863"/>
  </entry>
</feed>
