<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:16:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06966</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06966</link>
      <description>bdu:2026-06966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06966</guid>
    </item>
    <item>
      <title>EUVD-2026-318588</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318588</link>
      <description>EUVD-2026-318588</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318588</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44002</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44002</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2&amp;#39;s CallSite wrapper class (intended as a safe wrapper for V8&amp;#39;s native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server. This vulnerability is fixed in 3.11.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2&amp;#39;s CallSite wrapper class (intended as a safe wrapper for V8&amp;#39;s native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server. This vulnerability is fixed in 3.11.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44002</guid>
    </item>
    <item>
      <title>GHSA-v27g-jcqj-v8rw — vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v27g-jcqj-v8rw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary
vm2&amp;#39;s `CallSite` wrapper class (intended as a safe wrapper for V8&amp;#39;s native CallSite) blocks `getThis()` and `getFunction()` to prevent host object leakage, but allows `getFileName()` to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server.&lt;/p&gt;
&lt;p&gt;### Details
In `lib/setup-sandbox.js:436-466`, the `CallSite` class overrides `getThis()` and `getFunction()` with `undefined` to prevent host object references from leaking into the sandbox. However, the following methods pass through unsanitized values from the original V8 CallSite object:&lt;/p&gt;
&lt;p&gt;- `getFileName()` — returns host absolute paths like `/app/node_modules/vm2/lib/vm.js`
- `getLineNumber()`, `getColumnNumber()` — exact source locations
- `getFunctionName()`, `getMethodName()`, `getTypeName()` — internal function names&lt;/p&gt;
&lt;p&gt;Two exploitation paths exist:
1. **Default `error.stack`**: `new Error().stack` includes host frame paths in the formatted string
2. **Custom `prepareStackTrace`**: Attacker can set `Error.prepareStackTrace` to directly call `getFileName()` on each CallSite, extracting a clean list of all host paths&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Library-level PoC (Node.js script — primary):**
```javascript
const { VM } = require(&amp;#34;vm2&amp;#34;);
const vm = new VM();&lt;/p&gt;
&lt;p&gt;// Path A — Default error.stack
const result1 = vm.run(`try { null.x; } catch(e) { e.stack }`);
console.log(result1);
// Output includes: /app/node_modules/vm2/lib/vm.js:289:18
//…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary
vm2&amp;#39;s `CallSite` wrapper class (intended as a safe wrapper for V8&amp;#39;s native CallSite) blocks `getThis()` and `getFunction()` to prevent host object leakage, but allows `getFileName()` to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server.&lt;/p&gt;
&lt;p&gt;### Details
In `lib/setup-sandbox.js:436-466`, the `CallSite` class overrides `getThis()` and `getFunction()` with `undefined` to prevent host object references from leaking into the sandbox. However, the following methods pass through unsanitized values from the original V8 CallSite object:&lt;/p&gt;
&lt;p&gt;- `getFileName()` — returns host absolute paths like `/app/node_modules/vm2/lib/vm.js`
- `getLineNumber()`, `getColumnNumber()` — exact source locations
- `getFunctionName()`, `getMethodName()`, `getTypeName()` — internal function names&lt;/p&gt;
&lt;p&gt;Two exploitation paths exist:
1. **Default `error.stack`**: `new Error().stack` includes host frame paths in the formatted string
2. **Custom `prepareStackTrace`**: Attacker can set `Error.prepareStackTrace` to directly call `getFileName()` on each CallSite, extracting a clean list of all host paths&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Library-level PoC (Node.js script — primary):**
```javascript
const { VM } = require(&amp;#34;vm2&amp;#34;);
const vm = new VM();&lt;/p&gt;
&lt;p&gt;// Path A — Default error.stack
const result1 = vm.run(`try { null.x; } catch(e) { e.stack }`);
console.log(result1);
// Output includes: /app/node_modules/vm2/lib/vm.js:289:18
//…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v27g-jcqj-v8rw</guid>
    </item>
    <item>
      <title>RHSA-2026:50850 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:50850</link>
      <description>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators vm2: vm2: Arbitrary code execution via sandbox escape vm2: vm2: Remote code execution due to path restriction bypass via symlinks vm2: vm2: Remote code execution via NodeVM builtin allowlist bypass vm2: vm2: Sandbox escape allows direct interaction with host objects vm2: vm2: Sandbox escape leads to Denial of Service vm2: vm2: Information disclosure through unsanitized host paths vm2: vm2: Sandbox escape due to code transformer optimization bypass vm2: vm2: Denial of Service via host memory exhaustion vm2: vm2: Sandbox Escape leading to Arbitrary Code Execution vm2: vm2: Sandbox escape via arbitrary prototype access leading to arbitrary code execution vm2: vm2: Arbitrary code execution via nested NodeVM bypass vm2: vm2: Arbitrary code execution due to sandbox escape vm2: vm2: Arbitrary Code Execution via Sandbox Escape vm2: vm2: Arbitrary Code Execution due to sandbox escape vulnerability vm2: vm2: Arbitrary code execution via sandbox escape vulnerability vm2: vm2: Sandbox escape allows arbitrary code execution on the host system vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions vm2: vm2: NodeVM observability builtins leak host process and HTTP request data vm2: vm2: Integrity…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:50850</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1349 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1349</guid>
    </item>
  </channel>
</rss>
