<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:50:03.122855+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371545</id>
    <title>EUVD-2026-371545</title>
    <updated>2026-10-02T19:50:03.186210+00:00</updated>
    <content>EUVD-2026-371545</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92935</id>
    <title>fkie_cve-2026-92935</title>
    <updated>2026-10-02T19:50:03.186247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 is a sandbox for running untrusted Node.js code. In versions &gt;= 3.11.4 and &lt;= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' &amp;&amp; requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array into undefined option fields and returns a resolver containing only `NESTING_OVERRIDE.vm2`. As a result, an attacker who can supply JavaScript executed by a NodeVM configured with truthy `nesting` and an array-shaped `require` (e.g. `new NodeVM({nesting: true, require: []})`) can require the host `vm2` module, create an inner NodeVM with an attacker-chosen builtin allowlist (such as `child_process`), and execute arbitrary commands with the privileges of the host Node.js process, escaping the sandbox. Outer builtin restrictions do not constrain the attacker-created inner NodeVM. This issue is fixed in vm2 3.11.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8hr7-r645-pc6w</id>
    <title>GHSA-8hr7-r645-pc6w — vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE</title>
    <updated>2026-10-02T19:50:03.186288+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>## Summary</p>
<p>The `NodeVM` constructor computes `hasRealRequireConfig` using `typeof requireOpts === 'object' &amp;&amp; requireOpts !== null`, so `require: []` bypasses the guard intended to reject `nesting` without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array to undefined option fields and returns a resolver containing only `NESTING_OVERRIDE.vm2`. Any attacker whose JavaScript is executed by a downstream `NodeVM` configured with `{nesting: true, require: []}` can load the host `vm2` module, create an inner `NodeVM` with an attacker-selected builtin allowlist, and execute commands as the host process. No equivalent plain-object validation exists in `makeResolverFromLegacyOptions()`.</p>
<p>Array is converted into the vm2-only resolver:
https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/resolver-compat.js#L205-L226</p>
<p>Nesting loader returns the host VM constructors:
https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L640-L645</p>
<p>## Proof of Concept</p>
<p>Preconditions:</p>
<p>- The host creates `NodeVM` with truthy `nesting` and array-shaped `require`.
- The attacker can supply JavaScript executed by that `NodeVM`.</p>
<p>```javascript
'use strict';</p>
<p>const {NodeVM} = require('./index.js');</p>
<p>const outer = new NodeVM({nesting: true, require: []});
const result = outer.run(`
	const {NodeVM} = require('vm2');
	const inner = new NodeVM({require: {builtin: ['child_process']}});
	module.exp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8hr7-r645-pc6w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</id>
    <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:50:03.186338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997"/>
  </entry>
</feed>
