<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:57:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09619</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09619</link>
      <description>bdu:2026-09619</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09619</guid>
    </item>
    <item>
      <title>EUVD-2026-318169</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318169</link>
      <description>EUVD-2026-318169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318169</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44000</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44000</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox .then() callback preserves host identity. This allows the sandbox to interact with the host object directly, including performing identity checks using host-side WeakMap and mutating host object state from inside the sandbox. This behavior occurs because the Promise fulfillment wrapper uses ensureThis() instead of the stronger cross-realm conversion path (from() / proxy wrapping). If no prototype mapping is found, ensureThis() returns the original object. As a result, objects resolved by host Promises can cross the sandbox boundary without proper isolation. This vulnerability is fixed in 3.11.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox .then() callback preserves host identity. This allows the sandbox to interact with the host object directly, including performing identity checks using host-side WeakMap and mutating host object state from inside the sandbox. This behavior occurs because the Promise fulfillment wrapper uses ensureThis() instead of the stronger cross-realm conversion path (from() / proxy wrapping). If no prototype mapping is found, ensureThis() returns the original object. As a result, objects resolved by host Promises can cross the sandbox boundary without proper isolation. This vulnerability is fixed in 3.11.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44000</guid>
    </item>
    <item>
      <title>GHSA-mpf8-4hx2-7cjg — vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mpf8-4hx2-7cjg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A sandbox boundary violation in **vm2** allows host object identity to cross into the sandbox through host Promise resolution.&lt;/p&gt;
&lt;p&gt;When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox `.then()` callback preserves host identity. This allows the sandbox to interact with the host object directly, including:&lt;/p&gt;
&lt;p&gt;- Performing identity checks using host-side `WeakMap`
- Mutating host object state from inside the sandbox&lt;/p&gt;
&lt;p&gt;This behavior occurs because the Promise fulfillment wrapper uses `ensureThis()` instead of the stronger cross-realm conversion path (`from()` / proxy wrapping). If no prototype mapping is found, `ensureThis()` returns the original object.&lt;/p&gt;
&lt;p&gt;As a result, objects resolved by host Promises can cross the sandbox boundary without proper isolation.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `setup-sandbox.js`, vm2 wraps `Promise.prototype.then`:&lt;/p&gt;
&lt;p&gt;```js
globalPromise.prototype.then = function then(onFulfilled, onRejected) {
  resetPromiseSpecies(this);&lt;/p&gt;
&lt;p&gt;if (typeof onFulfilled === &amp;#39;function&amp;#39;) {
    const origOnFulfilled = onFulfilled;
    onFulfilled = function onFulfilled(value) {
      value = ensureThis(value);
      return apply(origOnFulfilled, this, [value]);
    };
  }&lt;/p&gt;
&lt;p&gt;return apply(globalPromiseThen, this, [onFulfilled, onRejected]);
};&lt;/p&gt;
&lt;p&gt;The wrapper calls ensureThis(value) before invoking the sandbox callback.&lt;/p&gt;
&lt;p&gt;However, ensureThis is implemented in bridge.js as thisEnsureThis():&lt;/p&gt;
&lt;p&gt;function thisEnsureThis(other…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A sandbox boundary violation in **vm2** allows host object identity to cross into the sandbox through host Promise resolution.&lt;/p&gt;
&lt;p&gt;When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox `.then()` callback preserves host identity. This allows the sandbox to interact with the host object directly, including:&lt;/p&gt;
&lt;p&gt;- Performing identity checks using host-side `WeakMap`
- Mutating host object state from inside the sandbox&lt;/p&gt;
&lt;p&gt;This behavior occurs because the Promise fulfillment wrapper uses `ensureThis()` instead of the stronger cross-realm conversion path (`from()` / proxy wrapping). If no prototype mapping is found, `ensureThis()` returns the original object.&lt;/p&gt;
&lt;p&gt;As a result, objects resolved by host Promises can cross the sandbox boundary without proper isolation.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `setup-sandbox.js`, vm2 wraps `Promise.prototype.then`:&lt;/p&gt;
&lt;p&gt;```js
globalPromise.prototype.then = function then(onFulfilled, onRejected) {
  resetPromiseSpecies(this);&lt;/p&gt;
&lt;p&gt;if (typeof onFulfilled === &amp;#39;function&amp;#39;) {
    const origOnFulfilled = onFulfilled;
    onFulfilled = function onFulfilled(value) {
      value = ensureThis(value);
      return apply(origOnFulfilled, this, [value]);
    };
  }&lt;/p&gt;
&lt;p&gt;return apply(globalPromiseThen, this, [onFulfilled, onRejected]);
};&lt;/p&gt;
&lt;p&gt;The wrapper calls ensureThis(value) before invoking the sandbox callback.&lt;/p&gt;
&lt;p&gt;However, ensureThis is implemented in bridge.js as thisEnsureThis():&lt;/p&gt;
&lt;p&gt;function thisEnsureThis(other…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mpf8-4hx2-7cjg</guid>
    </item>
    <item>
      <title>RHSA-2026:50850 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:50850</link>
      <description>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:50850</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1349 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</guid>
    </item>
  </channel>
</rss>
