<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:10:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03752</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03752</link>
      <description>bdu:2023-03752</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03752</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0529 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529</link>
      <description>certfr-2024-avi-0529</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529</guid>
    </item>
    <item>
      <title>EUVD-2026-264923</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264923</link>
      <description>EUVD-2026-264923</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264923</guid>
    </item>
    <item>
      <title>fkie_cve-2023-37466</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37466</link>
      <description>&lt;p&gt;vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with the `@@species` accessor property allowing attackers to escape the sandbox and run arbitrary code, potentially allowing remote code execution inside the context of vm2 sandbox. Version 3.10.0 contains a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with the `@@species` accessor property allowing attackers to escape the sandbox and run arbitrary code, potentially allowing remote code execution inside the context of vm2 sandbox. Version 3.10.0 contains a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-37466</guid>
    </item>
    <item>
      <title>GHSA-cchq-frgv-rjh5 — vm2 Sandbox Escape vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cchq-frgv-rjh5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed, allowing attackers to escape the sandbox and run arbitrary code.&lt;/p&gt;
&lt;p&gt;### Impact
Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
None.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
PoC - https://gist.github.com/leesh3288/f693061e6523c97274ad5298eb2c74e9&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open an issue in [VM2](https://github.com/patriksimek/vm2)&lt;/p&gt;
&lt;p&gt;Thanks to [Xion](https://twitter.com/0x10n) (SeungHyun Lee) of [KAIST Hacking Lab](https://kaist-hacking.github.io/) for disclosing this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed, allowing attackers to escape the sandbox and run arbitrary code.&lt;/p&gt;
&lt;p&gt;### Impact
Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
None.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
PoC - https://gist.github.com/leesh3288/f693061e6523c97274ad5298eb2c74e9&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open an issue in [VM2](https://github.com/patriksimek/vm2)&lt;/p&gt;
&lt;p&gt;Thanks to [Xion](https://twitter.com/0x10n) (SeungHyun Lee) of [KAIST Hacking Lab](https://kaist-hacking.github.io/) for disclosing this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cchq-frgv-rjh5</guid>
    </item>
    <item>
      <title>gsd-2023-37466</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-37466</link>
      <description>gsd-2023-37466</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-37466</guid>
    </item>
    <item>
      <title>RHSA-2023:4972 — Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.1.8 security updates and bug fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4972</link>
      <description>&lt;p&gt;openshift: OCP &amp;amp; FIPS mode vm2: Promise handler sanitization can be bypassed allowing attackers to escape the sandbox and run arbitrary code vm2: custom inspect function allows attackers to escape the sandbox and run arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openshift: OCP &amp;amp; FIPS mode vm2: Promise handler sanitization can be bypassed allowing attackers to escape the sandbox and run arbitrary code vm2: custom inspect function allows attackers to escape the sandbox and run arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4972</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1752 — vm2: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1752</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vm2 ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vm2 ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1752</guid>
    </item>
  </channel>
</rss>
