<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:09:59.162647+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15016</id>
    <title>bdu:2026-15016</title>
    <updated>2026-10-03T06:09:59.166739+00:00</updated>
    <content>bdu:2026-15016</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15016"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-370521</id>
    <title>EUVD-2026-370521</title>
    <updated>2026-10-03T06:09:59.166781+00:00</updated>
    <content>EUVD-2026-370521</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-370521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92945</id>
    <title>fkie_cve-2026-92945</title>
    <updated>2026-10-03T06:09:59.166807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7q3f-wx44-378m</id>
    <title>GHSA-7q3f-wx44-378m — vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted</title>
    <updated>2026-10-03T06:09:59.166851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>## Summary</p>
<p>`isPathAllowedForModule` decides whether a resolved path belongs to an allowlisted external module using a raw string prefix test. `node_modules/foo2` starts with `node_modules/foo`, so a package whose name merely shares a prefix with an allowlisted one is treated as being inside it, and a relative require from the allowlisted package reaches it even with transitive loading disabled.</p>
<p>## Where it is</p>
<p>`lib/resolver-compat.js`, lines 122 to 132, quoted from HEAD `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`:</p>
<p>```js
isPathAllowedForModule(path, mod) {
    if (!super.isPathAllowed(path)) return false;
    if (mod) {
        if (mod.allowTransitive) return true;
        if (path.startsWith(mod.path)) {
            const rem = path.slice(mod.path.length);
            if (!/(?:^|[\\/])node_modules(?:$|[\\/])/.test(rem)) return true;
        }
    }
    return this.externals.some(regex =&gt; regex.test(path));
}
```</p>
<p>With `mod.path` of `.../node_modules/foo` and a resolved path of `.../node_modules/foo2/index.js`, `startsWith` is true and `rem` is `2/index.js`, which contains no `node_modules` segment, so the function returns true.</p>
<p>The `node_modules` test in `rem` is what stops a genuine transitive dependency from slipping through. It does not stop a sibling, because a sibling's remainder never contains that segment.</p>
<p>## Impact</p>
<p>Code running in `NodeVM` under an external module allowlist with `transitive: false` can reach a package that was not allowlisted, provided an allowl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7q3f-wx44-378m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</id>
    <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:09:59.166929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997"/>
  </entry>
</feed>
