<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:27:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06428</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06428</link>
      <description>bdu:2026-06428</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06428</guid>
    </item>
    <item>
      <title>EUVD-2026-337434</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337434</link>
      <description>EUVD-2026-337434</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337434</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26956</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26956</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26956</guid>
    </item>
    <item>
      <title>GHSA-ffh4-j6h5-pg66 — VM2 Has a WASM Sandbox Escape</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ffh4-j6h5-pg66</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Full sandbox escape with arbitrary code execution. Attacker code inside `VM.run()` obtains host process object and runs host commands with zero host cooperation.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**Confirmed on:** vm2 3.10.4, Node.js v25.6.1 (x64 Linux)
**Trigger:** Attacker-controlled code passed to `VM.run()`
**Requires:** Node.js version with WebAssembly exception handling + JSTag support (tested on v25.6.1)&lt;/p&gt;
&lt;p&gt;vm2&amp;#39;s sandbox security relies on two JavaScript-level mechanisms: (1) a code transformer that injects `handleException()` into JS `catch` clauses to wrap host-realm errors, and (2) bridge Proxies that wrap cross-context objects. Both operate entirely within JavaScript.&lt;/p&gt;
&lt;p&gt;WebAssembly&amp;#39;s `try_table` instruction with a `JSTag` catch handler catches JavaScript exceptions at V8&amp;#39;s C++ level — below JavaScript entirely. When an imported JS function throws a TypeError produced by Symbol-to-string coercion during stack formatting (`e.name = Symbol(); e.stack`), the WASM `try_table` catches it as an opaque `externref` and returns it as a normal function return value. This WASM exception-handling-to-return-value path is not sanitized by vm2 — the host-realm TypeError reaches attacker code unsanitized. Its constructor chain (`hostError.constructor.constructor`) resolves to a Function that returns the host process object, allowing for reflection outside of the vm2 context, leading to code execution.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
const { VM } = require(&amp;#34;vm2&amp;#34;);
console.log(&amp;#34;vm2:&amp;#34;, require(&amp;#34;vm2/package.json&amp;#34;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Full sandbox escape with arbitrary code execution. Attacker code inside `VM.run()` obtains host process object and runs host commands with zero host cooperation.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**Confirmed on:** vm2 3.10.4, Node.js v25.6.1 (x64 Linux)
**Trigger:** Attacker-controlled code passed to `VM.run()`
**Requires:** Node.js version with WebAssembly exception handling + JSTag support (tested on v25.6.1)&lt;/p&gt;
&lt;p&gt;vm2&amp;#39;s sandbox security relies on two JavaScript-level mechanisms: (1) a code transformer that injects `handleException()` into JS `catch` clauses to wrap host-realm errors, and (2) bridge Proxies that wrap cross-context objects. Both operate entirely within JavaScript.&lt;/p&gt;
&lt;p&gt;WebAssembly&amp;#39;s `try_table` instruction with a `JSTag` catch handler catches JavaScript exceptions at V8&amp;#39;s C++ level — below JavaScript entirely. When an imported JS function throws a TypeError produced by Symbol-to-string coercion during stack formatting (`e.name = Symbol(); e.stack`), the WASM `try_table` catches it as an opaque `externref` and returns it as a normal function return value. This WASM exception-handling-to-return-value path is not sanitized by vm2 — the host-realm TypeError reaches attacker code unsanitized. Its constructor chain (`hostError.constructor.constructor`) resolves to a Function that returns the host process object, allowing for reflection outside of the vm2 context, leading to code execution.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
const { VM } = require(&amp;#34;vm2&amp;#34;);
console.log(&amp;#34;vm2:&amp;#34;, require(&amp;#34;vm2/package.json&amp;#34;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ffh4-j6h5-pg66</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1349 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</guid>
    </item>
  </channel>
</rss>
