<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:35:21.407177+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372355</id>
    <title>EUVD-2026-372355</title>
    <updated>2026-10-02T18:35:21.457305+00:00</updated>
    <content>EUVD-2026-372355</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92948</id>
    <title>fkie_cve-2026-92948</title>
    <updated>2026-10-02T18:35:21.457340+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 versions &gt;= 3.9.6 and &lt;= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it is stored in the generic host-passthrough loader. Because requireImpl() in lib/setup-node-sandbox.js strips a single 'node:' prefix before the builtin lookup, sandbox code calling require('node:node:test') resolves to the stored node:test key and receives a readonly proxy to the host module. Calls to node:test.run() are forwarded to the host implementation, which spawns a separate Node process for process-isolated test execution and passes through attacker-controlled execArgv values; supplying --eval=&lt;JavaScript&gt; therefore executes arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox. Fixed in vm2 3.11.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92948"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qhwx-74w5-xhxq</id>
    <title>GHSA-qhwx-74w5-xhxq — vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape</title>
    <updated>2026-10-02T18:35:21.457379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>## Summary</p>
<p>On Node.js 24 and newer, `vm2` can expose the host `node:test` module to sandboxed `NodeVM` code when the embedder explicitly allows the `node:test` builtin. Sandbox code can reach that module through `require('node:node:test')` and call `run()` with attacker-controlled `execArgv`.</p>
<p>`node:test.run()` starts a separate Node process for process-isolated test execution and forwards the supplied `execArgv` values to that process. Supplying `--eval=&lt;JavaScript&gt;` therefore executes arbitrary JavaScript in an unrestricted host Node process, outside the `NodeVM` sandbox.</p>
<p>The PoC confirms that direct sandbox imports of `fs`, `child_process`, `module`, and `process` remain denied before the spawned process imports host `fs` and writes a harmless marker.</p>
<p>## Affected versions and environment</p>
<p>- Package: `vm2`
- Affected versions: `&gt;=3.9.6, &lt;=3.11.5`
- Latest reproduced version: `3.11.5`
- Reproduced runtime: Node.js `v24.18.0`
- Exact path is not present on Node.js 22 because `module.builtinModules` does not expose the scheme-only `node:test` entry there
- Configuration prerequisite:</p>
<p>```js
require: {
  builtin: ['node:test'],
  external: false
}
```</p>
<p>The lower version boundary was tested directly: `vm2@3.9.5` blocks `require('node:node:test')`, while `vm2@3.9.6` permits the exploit path. Representative releases through `3.11.5` were also reproduced.</p>
<p>## Root cause</p>
<p>The issue is a combination of builtin admission, generic host passthrough, and prefix normalization:</p>
<p>1. On…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qhwx-74w5-xhxq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</id>
    <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:35:21.457437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997"/>
  </entry>
</feed>
