<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:43:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326993</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326993</link>
      <description>EUVD-2026-326993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326993</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47137</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47137</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely. When require is not specified, options.require is undefined, not false. The strict equality check fails, so the security guard is skipped. Immediately after (line 280), the destructuring default require: requireOpts = false assigns requireOpts = false, producing the exact configuration the patch was designed to prevent. This issue has been patched in version 3.11.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely. When require is not specified, options.require is undefined, not false. The strict equality check fails, so the security guard is skipped. Immediately after (line 280), the destructuring default require: requireOpts = false assigns requireOpts = false, producing the exact configuration the patch was designed to prevent. This issue has been patched in version 3.11.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47137</guid>
    </item>
    <item>
      <title>GHSA-m4wx-m65x-ghrr — vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m4wx-m65x-ghrr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in `nodevm.js` line 263 that blocks the combination `nesting: true` + `require: false`. However, the check uses strict equality (`options.require === false`), which is trivially bypassed by omitting the `require` option entirely.&lt;/p&gt;
&lt;p&gt;When `require` is not specified, `options.require` is `undefined`, not `false`. The strict equality check fails, so the security guard is skipped. Immediately after (line 280), the destructuring default `require: requireOpts = false` assigns `requireOpts = false`, producing the exact configuration the patch was designed to prevent.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;```javascript
// nodevm.js:263 — the security check
if (options.nesting === true &amp;amp;&amp;amp; options.require === false) {
    throw new VMError(&amp;#39;...&amp;#39;);
}
// nodevm.js:280 — the default assignment (AFTER the check)
const { require: requireOpts = false } = options;
// When options.require is undefined:
//   - Line 263: undefined === false → FALSE → check skipped
//   - Line 280: requireOpts = false → same as require:false
```&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Full Remote Code Execution on the host system. An attacker running code inside a `NodeVM({ nesting: true })` sandbox (without specifying `require`) can:&lt;/p&gt;
&lt;p&gt;1. `require(&amp;#39;vm2&amp;#39;)` to get the vm2 library
2. Construct an inner `NodeVM` with `require: { builtin: [&amp;#39;child_process&amp;#39;] }`
3. Execute arbitrary OS commands via `child_process.execSync`&lt;/p&gt;
&lt;p&gt;The inner VM is completely unconstrained by the outer sandbox configu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in `nodevm.js` line 263 that blocks the combination `nesting: true` + `require: false`. However, the check uses strict equality (`options.require === false`), which is trivially bypassed by omitting the `require` option entirely.&lt;/p&gt;
&lt;p&gt;When `require` is not specified, `options.require` is `undefined`, not `false`. The strict equality check fails, so the security guard is skipped. Immediately after (line 280), the destructuring default `require: requireOpts = false` assigns `requireOpts = false`, producing the exact configuration the patch was designed to prevent.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;```javascript
// nodevm.js:263 — the security check
if (options.nesting === true &amp;amp;&amp;amp; options.require === false) {
    throw new VMError(&amp;#39;...&amp;#39;);
}
// nodevm.js:280 — the default assignment (AFTER the check)
const { require: requireOpts = false } = options;
// When options.require is undefined:
//   - Line 263: undefined === false → FALSE → check skipped
//   - Line 280: requireOpts = false → same as require:false
```&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Full Remote Code Execution on the host system. An attacker running code inside a `NodeVM({ nesting: true })` sandbox (without specifying `require`) can:&lt;/p&gt;
&lt;p&gt;1. `require(&amp;#39;vm2&amp;#39;)` to get the vm2 library
2. Construct an inner `NodeVM` with `require: { builtin: [&amp;#39;child_process&amp;#39;] }`
3. Execute arbitrary OS commands via `child_process.execSync`&lt;/p&gt;
&lt;p&gt;The inner VM is completely unconstrained by the outer sandbox configu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m4wx-m65x-ghrr</guid>
    </item>
    <item>
      <title>RHSA-2026:33574 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.6 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33574</link>
      <description>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass. crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/mail: golang: Go net/mail: Denial of Service via crafted email inputs axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axios: Axios: NO_PROXY bypass via crafted URL axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input net/mail: golang: net/mail: Denial of Service via pathological email address parsing axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass. crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/mail: golang: Go net/mail: Denial of Service via crafted email inputs axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axios: Axios: NO_PROXY bypass via crafted URL axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input net/mail: golang: net/mail: Denial of Service via pathological email address parsing axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33574</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1583 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1583</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1583</guid>
    </item>
  </channel>
</rss>
