<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:27:18.669598+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15023</id>
    <title>bdu:2026-15023</title>
    <updated>2026-10-02T17:27:18.755480+00:00</updated>
    <content>bdu:2026-15023</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372358</id>
    <title>EUVD-2026-372358</title>
    <updated>2026-10-02T17:27:18.755517+00:00</updated>
    <content>EUVD-2026-372358</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92958</id>
    <title>fkie_cve-2026-92958</title>
    <updated>2026-10-02T17:27:18.755533+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched by exact module name in lib/builtin.js, so -fs removes only the builtin named fs and does not remove builtin subpaths such as fs/promises. Sandboxed code can therefore call require('fs/promises') or require('node:fs/promises') and reach the promise-based filesystem API despite fs being denied; node: prefix handling is likewise inconsistent (a -node:fs/promises entry does not block require('fs/promises')). Host file creation and writing were confirmed via fsp.writeFile(), and other fs/promises operations (cp, mkdir, rename, rm, rmdir, truncate, read operations, etc.) are also reachable. This issue is fixed in vm2 3.11.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6rh5-qq4q-97xh</id>
    <title>GHSA-6rh5-qq4q-97xh — vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes</title>
    <updated>2026-10-02T17:27:18.755569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>## Summary</p>
<p>NodeVM's builtin wildcard policy can allow sandboxed code to access `fs/promises` even when the embedder denies `fs`.</p>
<p>With the following configuration:</p>
<p>```js
require: {
  builtin: ['*', '-fs', '-child_process']
}
```</p>
<p>`require('fs')` and `require('child_process')` are blocked, but `require('fs/promises')` and `require('node:fs/promises')` are still available. This allows sandboxed code to create and write files on the host filesystem through the promise-based filesystem API.</p>
<p>## Affected Mode</p>
<p>NodeVM.</p>
<p>## Affected Configuration</p>
<p>```js
new NodeVM({
  require: {
    builtin: ['*', '-fs', '-child_process']
  }
});
```</p>
<p>This affects configurations where users rely on negative builtin entries such as `-fs` to deny filesystem access while using the `'*'` builtin wildcard.</p>
<p>## Affected Files / Functions</p>
<p>- `lib/builtin.js`
  - `DANGEROUS_BUILTINS`
  - `BUILTIN_MODULES`
  - `makeBuiltinsFromLegacyOptions`
  - `addDefaultBuiltin`
- `lib/resolver.js`
  - `Resolver.resolve`
  - `Resolver.loadBuiltinModule`
- `lib/setup-node-sandbox.js`
  - `requireImpl`</p>
<p>## Root Cause</p>
<p>`lib/builtin.js` builds `BUILTIN_MODULES` from Node's builtin module list and filters dangerous/default-denied modules. In wildcard mode, negative entries are checked by exact name:</p>
<p>```js
if (builtins.indexOf(`-${name}`) === -1) {
  addDefaultBuiltin(res, name, hostRequire);
}
```</p>
<p>This means `-fs` removes only the exact builtin named `fs`. It does not remove builtin subpaths such as `fs/promises`.</p>
<p>There…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6rh5-qq4q-97xh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:72712</id>
    <title>RHSA-2026:72712 — Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update</title>
    <updated>2026-10-02T17:27:18.755632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>multer: Multer: Denial of Service via aborted or malformed multipart uploads undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass urllib: urllib: Credential leakage via cross-origin redirects js-yaml: js-yaml: Denial of Service via crafted YAML documents immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations qs: qs: Denial of Service via improper validation in stringify function js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing compression: compression: Denial of Service via memory leak on premature response close multer: multer: Denial of Service via orphaned disk writes on aborted uploads isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size vm2: vm2: Denial of Service via timeout bypass in sandboxed code vm2: vm2: Sandbox escape via denylist bypass in NodeVM vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation vm2: vm2: Denial of Service via memory exhaustion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:72712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</id>
    <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:27:18.755684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997"/>
  </entry>
</feed>
