<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:07:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15016</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15016</link>
      <description>bdu:2026-15016</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15016</guid>
    </item>
    <item>
      <title>EUVD-2026-370521</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370521</link>
      <description>EUVD-2026-370521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370521</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92945</link>
      <description>&lt;p&gt;vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92945</guid>
    </item>
    <item>
      <title>GHSA-7q3f-wx44-378m — vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7q3f-wx44-378m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`isPathAllowedForModule` decides whether a resolved path belongs to an allowlisted external module using a raw string prefix test. `node_modules/foo2` starts with `node_modules/foo`, so a package whose name merely shares a prefix with an allowlisted one is treated as being inside it, and a relative require from the allowlisted package reaches it even with transitive loading disabled.&lt;/p&gt;
&lt;p&gt;## Where it is&lt;/p&gt;
&lt;p&gt;`lib/resolver-compat.js`, lines 122 to 132, quoted from HEAD `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`:&lt;/p&gt;
&lt;p&gt;```js
isPathAllowedForModule(path, mod) {
    if (!super.isPathAllowed(path)) return false;
    if (mod) {
        if (mod.allowTransitive) return true;
        if (path.startsWith(mod.path)) {
            const rem = path.slice(mod.path.length);
            if (!/(?:^|[\\/])node_modules(?:$|[\\/])/.test(rem)) return true;
        }
    }
    return this.externals.some(regex =&amp;gt; regex.test(path));
}
```&lt;/p&gt;
&lt;p&gt;With `mod.path` of `.../node_modules/foo` and a resolved path of `.../node_modules/foo2/index.js`, `startsWith` is true and `rem` is `2/index.js`, which contains no `node_modules` segment, so the function returns true.&lt;/p&gt;
&lt;p&gt;The `node_modules` test in `rem` is what stops a genuine transitive dependency from slipping through. It does not stop a sibling, because a sibling&amp;#39;s remainder never contains that segment.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Code running in `NodeVM` under an external module allowlist with `transitive: false` can reach a package that was not allowlisted, provided an allowl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`isPathAllowedForModule` decides whether a resolved path belongs to an allowlisted external module using a raw string prefix test. `node_modules/foo2` starts with `node_modules/foo`, so a package whose name merely shares a prefix with an allowlisted one is treated as being inside it, and a relative require from the allowlisted package reaches it even with transitive loading disabled.&lt;/p&gt;
&lt;p&gt;## Where it is&lt;/p&gt;
&lt;p&gt;`lib/resolver-compat.js`, lines 122 to 132, quoted from HEAD `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`:&lt;/p&gt;
&lt;p&gt;```js
isPathAllowedForModule(path, mod) {
    if (!super.isPathAllowed(path)) return false;
    if (mod) {
        if (mod.allowTransitive) return true;
        if (path.startsWith(mod.path)) {
            const rem = path.slice(mod.path.length);
            if (!/(?:^|[\\/])node_modules(?:$|[\\/])/.test(rem)) return true;
        }
    }
    return this.externals.some(regex =&amp;gt; regex.test(path));
}
```&lt;/p&gt;
&lt;p&gt;With `mod.path` of `.../node_modules/foo` and a resolved path of `.../node_modules/foo2/index.js`, `startsWith` is true and `rem` is `2/index.js`, which contains no `node_modules` segment, so the function returns true.&lt;/p&gt;
&lt;p&gt;The `node_modules` test in `rem` is what stops a genuine transitive dependency from slipping through. It does not stop a sibling, because a sibling&amp;#39;s remainder never contains that segment.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Code running in `NodeVM` under an external module allowlist with `transitive: false` can reach a package that was not allowlisted, provided an allowl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7q3f-wx44-378m</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</guid>
    </item>
  </channel>
</rss>
