<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:12:20 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14939</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14939</link>
      <description>bdu:2026-14939</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14939</guid>
    </item>
    <item>
      <title>EUVD-2026-372450</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372450</link>
      <description>EUVD-2026-372450</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372450</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92938</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92938</link>
      <description>&lt;p&gt;vm2 versions 3.11.3 through 3.11.6 expose Node.js&amp;#39;s host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: [&amp;#39;*&amp;#39;]. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with &amp;#39;node:&amp;#39; as a core-module request and the runtime strips only one &amp;#39;node:&amp;#39; prefix, so a sandbox request for &amp;#39;node:node:sqlite&amp;#39; resolves to the configured node:sqlite entry. Sandboxed code can therefore create an in-memory DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library bundled in the untrusted plugin package (path derived from __dirname). SQLite loads the library into the Node.js host process and invokes its native entry point, giving the sandboxed plugin arbitrary native code execution outside the sandbox with the host process&amp;#39;s privileges. The issue is fixed in vm2 3.11.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 versions 3.11.3 through 3.11.6 expose Node.js&amp;#39;s host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: [&amp;#39;*&amp;#39;]. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with &amp;#39;node:&amp;#39; as a core-module request and the runtime strips only one &amp;#39;node:&amp;#39; prefix, so a sandbox request for &amp;#39;node:node:sqlite&amp;#39; resolves to the configured node:sqlite entry. Sandboxed code can therefore create an in-memory DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library bundled in the untrusted plugin package (path derived from __dirname). SQLite loads the library into the Node.js host process and invokes its native entry point, giving the sandboxed plugin arbitrary native code execution outside the sandbox with the host process&amp;#39;s privileges. The issue is fixed in vm2 3.11.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92938</guid>
    </item>
    <item>
      <title>GHSA-6w8r-xxw2-g3hx — vm2 allows a sandboxed plugin to execute native code through `node:sqlite`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6w8r-xxw2-g3hx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;vm2 3.11.6 exposes Node.js&amp;#39;s host `node:sqlite` module to `NodeVM` code when that builtin is allowed explicitly or through `builtin: [&amp;#39;*&amp;#39;]`. The module is wrapped as read-only, but callable methods retain host-process authority. A sandboxed plugin can construct an in-memory database with extension loading enabled and call `DatabaseSync.loadExtension()` on a native library bundled in the plugin directory.&lt;/p&gt;
&lt;p&gt;SQLite loads the library into the Node.js host process and invokes its native extension entry point. This gives the untrusted plugin arbitrary native code execution outside the sandbox.&lt;/p&gt;
&lt;p&gt;The exploit needs only the `node:sqlite` builtin and a compatible native library already present in the untrusted plugin package. It does not require `fs`, `process`, `module`, `child_process`, `worker_threads`, `vm`, `inspector`, vm2 nesting, or an existing database file.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable boundary spans the builtin inventory, resolver, runtime loader, and generic read-only wrapper.&lt;/p&gt;
&lt;p&gt;On current Node.js versions, the builtin inventory contains the literal name `node:sqlite`. vm2 admits that name when it is explicitly configured or when the wildcard allowlist is expanded:&lt;/p&gt;
&lt;p&gt;```js
const BUILTIN_MODULES = module.builtinModules.filter(/* denylist checks */);
```&lt;/p&gt;
&lt;p&gt;The resolver then treats every request beginning with `node:` as a core-module request, even if the complete request string is not an allowlist key:&lt;/p&gt;
&lt;p&gt;```js
if (x.startsWith(&amp;#39;node:&amp;#39;) || this.builtins.has(x)) {
  r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;vm2 3.11.6 exposes Node.js&amp;#39;s host `node:sqlite` module to `NodeVM` code when that builtin is allowed explicitly or through `builtin: [&amp;#39;*&amp;#39;]`. The module is wrapped as read-only, but callable methods retain host-process authority. A sandboxed plugin can construct an in-memory database with extension loading enabled and call `DatabaseSync.loadExtension()` on a native library bundled in the plugin directory.&lt;/p&gt;
&lt;p&gt;SQLite loads the library into the Node.js host process and invokes its native extension entry point. This gives the untrusted plugin arbitrary native code execution outside the sandbox.&lt;/p&gt;
&lt;p&gt;The exploit needs only the `node:sqlite` builtin and a compatible native library already present in the untrusted plugin package. It does not require `fs`, `process`, `module`, `child_process`, `worker_threads`, `vm`, `inspector`, vm2 nesting, or an existing database file.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable boundary spans the builtin inventory, resolver, runtime loader, and generic read-only wrapper.&lt;/p&gt;
&lt;p&gt;On current Node.js versions, the builtin inventory contains the literal name `node:sqlite`. vm2 admits that name when it is explicitly configured or when the wildcard allowlist is expanded:&lt;/p&gt;
&lt;p&gt;```js
const BUILTIN_MODULES = module.builtinModules.filter(/* denylist checks */);
```&lt;/p&gt;
&lt;p&gt;The resolver then treats every request beginning with `node:` as a core-module request, even if the complete request string is not an allowlist key:&lt;/p&gt;
&lt;p&gt;```js
if (x.startsWith(&amp;#39;node:&amp;#39;) || this.builtins.has(x)) {
  r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6w8r-xxw2-g3hx</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</guid>
    </item>
  </channel>
</rss>
