<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:10:10.833680+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14943</id>
    <title>bdu:2026-14943</title>
    <updated>2026-10-02T22:10:10.899916+00:00</updated>
    <content>bdu:2026-14943</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14943"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-370519</id>
    <title>EUVD-2026-370519</title>
    <updated>2026-10-02T22:10:10.899951+00:00</updated>
    <content>EUVD-2026-370519</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-370519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92950</id>
    <title>fkie_cve-2026-92950</title>
    <updated>2026-10-02T22:10:10.899966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jxxv-8r27-vm4p</id>
    <title>GHSA-jxxv-8r27-vm4p — vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts</title>
    <updated>2026-10-02T22:10:10.899997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>### Summary
The `vm2` command-line tool installed by `npm install -g vm2` and documented in the README's "CLI" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver loads every relative or absolute `require()` target through the **host** `require()` function, executing the attacker's module body in the host Node.js process before the result is ever proxied back into the sandbox. A single attacker-controlled file passed to `vm2 ./script.js` can call `require(__filename)` to re-execute itself in host realm and reach `fs`, `child_process`, etc. The documented sandbox runner is therefore equivalent to `node ./script.js`. No additional files, flags, or user interaction are required.</p>
<p>### Details
The vulnerability lets a **malicious sandboxed script** - the file argument to the documented `vm2 &lt;file&gt;` CLI - execute arbitrary code in the **host Node.js process**, crossing the sandbox → host boundary that vm2 is meant to enforce.</p>
<p>#### Vulnerable code path</p>
<p>1. **Source** - `bin/vm2:3` → `lib/cli.js:7-18`. `process.argv[2]` is the
   attacker-authored script path. The CLI invokes:
   ```js
   NodeVM.file(path, { verbose: true, require: { external: true } });
   ```
   Without `require.root`, `require.context`, nor `require.builtin`.
2. **Hop** - `lib/nodevm.js:618-636`. `NodeVM.file` reads the file and calls
   `new NodeVM(options).run(body, resolvedFilename)`.
3. **Hop** - `li…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jxxv-8r27-vm4p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</id>
    <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:10:10.900054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997"/>
  </entry>
</feed>
