<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:12:49.498489+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15021</id>
    <title>bdu:2026-15021</title>
    <updated>2026-10-02T15:12:49.569463+00:00</updated>
    <content>bdu:2026-15021</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377260</id>
    <title>EUVD-2026-377260</title>
    <updated>2026-10-02T15:12:49.569498+00:00</updated>
    <content>EUVD-2026-377260</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377260"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92957</id>
    <title>fkie_cve-2026-92957</title>
    <updated>2026-10-02T15:12:49.569513+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-node:child_process'] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require('child_process')` or `require('node:child_process')`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92957"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8686-vhfx-7r3j</id>
    <title>GHSA-8686-vhfx-7r3j — vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process</title>
    <updated>2026-10-02T15:12:49.569547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>## Summary</p>
<p>NodeVM normalizes `node:`-prefixed builtin specifiers during `require()` resolution, but it does not normalize user-provided negative builtin entries in wildcard policy.</p>
<p>As a result, this configuration:</p>
<p>```js
new NodeVM({
  require: {
    builtin: ['*', '-node:child_process']
  }
});
```</p>
<p>does not deny the canonical `child_process` builtin. Sandboxed code can require both `child_process` and `node:child_process`, and receives the host module with process-spawning APIs such as `execSync` and `spawn`.</p>
<p>The safe proof below only checks module and function reachability. It does not execute any OS command.</p>
<p>## Affected Mode</p>
<p>NodeVM.</p>
<p>## Affected Configuration</p>
<p>```js
new NodeVM({
  require: {
    builtin: ['*', '-node:child_process']
  }
});
```</p>
<p>This affects users who deny builtins using their `node:`-prefixed spelling, expecting `-node:child_process` to deny `require('node:child_process')` and `require('child_process')`.</p>
<p>## Affected Files / Functions</p>
<p>- `lib/builtin.js`
  - `makeBuiltinsFromLegacyOptions`
  - wildcard builtin expansion
  - exact negative entry check: `builtins.indexOf(\`-${name}\`)`
  - `addDefaultBuiltin`
- `lib/resolver.js`
  - `Resolver.resolve`
- `lib/setup-node-sandbox.js`
  - `requireImpl`
  - `node:` prefix stripping before builtin load</p>
<p>## Root Cause</p>
<p>`lib/setup-node-sandbox.js` strips the `node:` prefix from resolved builtin filenames before loading the builtin:</p>
<p>```js
if (localStringPrototypeStartsWith(filename, 'node:')) {
  id = localS…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8686-vhfx-7r3j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</id>
    <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:12:49.569611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997"/>
  </entry>
</feed>
