<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:19:25.062993+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373051</id>
    <title>EUVD-2026-373051</title>
    <updated>2026-10-02T21:19:25.168499+00:00</updated>
    <content>EUVD-2026-373051</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373051"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92949</id>
    <title>fkie_cve-2026-92949</title>
    <updated>2026-10-02T21:19:25.168580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-633r-hq9m-c4ff</id>
    <title>GHSA-633r-hq9m-c4ff — vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor</title>
    <updated>2026-10-02T21:19:25.168640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>### Summary
Untrusted JavaScript running inside `new VM().run()` / `new NodeVM().run()` can bypass `vm.freeze()` / `vm.readonly()` and mutate a host object the embedder explicitly marked read-only - the documented contract is "prevent sandboxed scripts from adding, changing, or deleting properties". If the frozen host object has an accessor (get/set) own-property, the sandbox can read the host setter back out via `Object.getOwnPropertyDescriptor()` and call it directly; the call lands in `BaseHandler.apply` which unwraps the readonly proxy to the raw host object and runs the host setter against it. No non-default `VM`/`NodeVM` options are required; the only precondition is that the embedder froze an object whose shape includes an accessor property. A second route to the same sink exists via `__lookupSetter__`.</p>
<p>### PoC
```js
// poc.js
'use strict';
const { VM } = require('vm2');</p>
<p>let _level = 'safe';
const hostConfig = Object.defineProperty({}, 'level', {
  get() { return _level; },
  set(v) { _level = String(v); },
  enumerable: true, configurable: true,
});</p>
<p>const vm = new VM();
vm.freeze(hostConfig, 'cfg');</p>
<p>// Baseline - documented barriers hold:
vm.run(`cfg.level = 'via-set';`);
vm.run(`try { Object.defineProperty(cfg, 'level', {value: 'via-dP'}); } catch (e) {}`);
console.log('after [[Set]]/defineProperty:', _level);   // → "safe"</p>
<p>// Bypass - sandbox mutates host via accessor descriptor:
vm.run(`
  const d = Object.getOwnPropertyDescriptor(cfg, 'level');
  d.set.call(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-633r-hq9m-c4ff"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</id>
    <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:19:25.168811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997"/>
  </entry>
</feed>
