<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:14:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15021</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15021</link>
      <description>bdu:2026-15021</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15021</guid>
    </item>
    <item>
      <title>EUVD-2026-377260</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-377260</link>
      <description>EUVD-2026-377260</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-377260</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92957</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92957</link>
      <description>&lt;p&gt;vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: [&amp;#39;*&amp;#39;, &amp;#39;-node:child_process&amp;#39;] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require(&amp;#39;child_process&amp;#39;)` or `require(&amp;#39;node:child_process&amp;#39;)`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: [&amp;#39;*&amp;#39;, &amp;#39;-node:child_process&amp;#39;] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require(&amp;#39;child_process&amp;#39;)` or `require(&amp;#39;node:child_process&amp;#39;)`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92957</guid>
    </item>
    <item>
      <title>GHSA-8686-vhfx-7r3j — vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8686-vhfx-7r3j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;NodeVM normalizes `node:`-prefixed builtin specifiers during `require()` resolution, but it does not normalize user-provided negative builtin entries in wildcard policy.&lt;/p&gt;
&lt;p&gt;As a result, this configuration:&lt;/p&gt;
&lt;p&gt;```js
new NodeVM({
  require: {
    builtin: [&amp;#39;*&amp;#39;, &amp;#39;-node:child_process&amp;#39;]
  }
});
```&lt;/p&gt;
&lt;p&gt;does not deny the canonical `child_process` builtin. Sandboxed code can require both `child_process` and `node:child_process`, and receives the host module with process-spawning APIs such as `execSync` and `spawn`.&lt;/p&gt;
&lt;p&gt;The safe proof below only checks module and function reachability. It does not execute any OS command.&lt;/p&gt;
&lt;p&gt;## Affected Mode&lt;/p&gt;
&lt;p&gt;NodeVM.&lt;/p&gt;
&lt;p&gt;## Affected Configuration&lt;/p&gt;
&lt;p&gt;```js
new NodeVM({
  require: {
    builtin: [&amp;#39;*&amp;#39;, &amp;#39;-node:child_process&amp;#39;]
  }
});
```&lt;/p&gt;
&lt;p&gt;This affects users who deny builtins using their `node:`-prefixed spelling, expecting `-node:child_process` to deny `require(&amp;#39;node:child_process&amp;#39;)` and `require(&amp;#39;child_process&amp;#39;)`.&lt;/p&gt;
&lt;p&gt;## Affected Files / Functions&lt;/p&gt;
&lt;p&gt;- `lib/builtin.js`
  - `makeBuiltinsFromLegacyOptions`
  - wildcard builtin expansion
  - exact negative entry check: `builtins.indexOf(\`-${name}\`)`
  - `addDefaultBuiltin`
- `lib/resolver.js`
  - `Resolver.resolve`
- `lib/setup-node-sandbox.js`
  - `requireImpl`
  - `node:` prefix stripping before builtin load&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`lib/setup-node-sandbox.js` strips the `node:` prefix from resolved builtin filenames before loading the builtin:&lt;/p&gt;
&lt;p&gt;```js
if (localStringPrototypeStartsWith(filename, &amp;#39;node:&amp;#39;)) {
  id = localS…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;NodeVM normalizes `node:`-prefixed builtin specifiers during `require()` resolution, but it does not normalize user-provided negative builtin entries in wildcard policy.&lt;/p&gt;
&lt;p&gt;As a result, this configuration:&lt;/p&gt;
&lt;p&gt;```js
new NodeVM({
  require: {
    builtin: [&amp;#39;*&amp;#39;, &amp;#39;-node:child_process&amp;#39;]
  }
});
```&lt;/p&gt;
&lt;p&gt;does not deny the canonical `child_process` builtin. Sandboxed code can require both `child_process` and `node:child_process`, and receives the host module with process-spawning APIs such as `execSync` and `spawn`.&lt;/p&gt;
&lt;p&gt;The safe proof below only checks module and function reachability. It does not execute any OS command.&lt;/p&gt;
&lt;p&gt;## Affected Mode&lt;/p&gt;
&lt;p&gt;NodeVM.&lt;/p&gt;
&lt;p&gt;## Affected Configuration&lt;/p&gt;
&lt;p&gt;```js
new NodeVM({
  require: {
    builtin: [&amp;#39;*&amp;#39;, &amp;#39;-node:child_process&amp;#39;]
  }
});
```&lt;/p&gt;
&lt;p&gt;This affects users who deny builtins using their `node:`-prefixed spelling, expecting `-node:child_process` to deny `require(&amp;#39;node:child_process&amp;#39;)` and `require(&amp;#39;child_process&amp;#39;)`.&lt;/p&gt;
&lt;p&gt;## Affected Files / Functions&lt;/p&gt;
&lt;p&gt;- `lib/builtin.js`
  - `makeBuiltinsFromLegacyOptions`
  - wildcard builtin expansion
  - exact negative entry check: `builtins.indexOf(\`-${name}\`)`
  - `addDefaultBuiltin`
- `lib/resolver.js`
  - `Resolver.resolve`
- `lib/setup-node-sandbox.js`
  - `requireImpl`
  - `node:` prefix stripping before builtin load&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`lib/setup-node-sandbox.js` strips the `node:` prefix from resolved builtin filenames before loading the builtin:&lt;/p&gt;
&lt;p&gt;```js
if (localStringPrototypeStartsWith(filename, &amp;#39;node:&amp;#39;)) {
  id = localS…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8686-vhfx-7r3j</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</guid>
    </item>
  </channel>
</rss>
