<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:36:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03966</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03966</link>
      <description>bdu:2023-03966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03966</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0529 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529</link>
      <description>certfr-2024-avi-0529</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0529</guid>
    </item>
    <item>
      <title>EUVD-2026-258441</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258441</link>
      <description>EUVD-2026-258441</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258441</guid>
    </item>
    <item>
      <title>fkie_cve-2023-37903</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37903</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-37903</guid>
    </item>
    <item>
      <title>GHSA-g644-9gfx-q4q4 — vm2 Sandbox Escape vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g644-9gfx-q4q4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;In vm2 for versions up to 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code.&lt;/p&gt;
&lt;p&gt;### Impact
Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
None.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
PoC is to be disclosed on or after the 5th of September.&lt;/p&gt;
&lt;p&gt;### Similarity with [CVE-2023-37466](https://nvd.nist.gov/vuln/detail/CVE-2023-37466)
While this advisory might look similar to [CVE-2023-37466](https://nvd.nist.gov/vuln/detail/CVE-2023-37466), it is a completely different way of escaping the sandbox.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open an issue in [VM2](https://github.com/patriksimek/vm2)&lt;/p&gt;
&lt;p&gt;Thanks to [Xion](https://twitter.com/0x10n) (SeungHyun Lee) of [KAIST Hacking Lab](https://kaist-hacking.github.io/) for disclosing this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;In vm2 for versions up to 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code.&lt;/p&gt;
&lt;p&gt;### Impact
Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
None.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
PoC is to be disclosed on or after the 5th of September.&lt;/p&gt;
&lt;p&gt;### Similarity with [CVE-2023-37466](https://nvd.nist.gov/vuln/detail/CVE-2023-37466)
While this advisory might look similar to [CVE-2023-37466](https://nvd.nist.gov/vuln/detail/CVE-2023-37466), it is a completely different way of escaping the sandbox.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open an issue in [VM2](https://github.com/patriksimek/vm2)&lt;/p&gt;
&lt;p&gt;Thanks to [Xion](https://twitter.com/0x10n) (SeungHyun Lee) of [KAIST Hacking Lab](https://kaist-hacking.github.io/) for disclosing this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g644-9gfx-q4q4</guid>
    </item>
    <item>
      <title>gsd-2023-37903</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-37903</link>
      <description>gsd-2023-37903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-37903</guid>
    </item>
    <item>
      <title>RHSA-2023:4972 — Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.1.8 security updates and bug fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4972</link>
      <description>&lt;p&gt;openshift: OCP &amp;amp; FIPS mode vm2: Promise handler sanitization can be bypassed allowing attackers to escape the sandbox and run arbitrary code vm2: custom inspect function allows attackers to escape the sandbox and run arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openshift: OCP &amp;amp; FIPS mode vm2: Promise handler sanitization can be bypassed allowing attackers to escape the sandbox and run arbitrary code vm2: custom inspect function allows attackers to escape the sandbox and run arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4972</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1863 — vm2: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1863</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vm2 ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vm2 ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1863</guid>
    </item>
  </channel>
</rss>
