<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 03:38:25 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-92955 — vm2 before 3.11.8 Sandbox Escape via NodeVM</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-92955</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; patriksimek vm2&lt;/p&gt;
&lt;p&gt;vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; patriksimek vm2&lt;/p&gt;
&lt;p&gt;vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-92955</guid>
    </item>
    <item>
      <title>GHSA-88hf-g992-jg85 — vm2: Sandbox Escape (NodeVM)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-88hf-g992-jg85</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;It being possible to obtain the host `__proto__` getter/setter, has been used in many reports:&lt;/p&gt;
&lt;p&gt;- https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq
- https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg
- https://github.com/patriksimek/vm2/security/advisories/GHSA-grj5-jjm8-h35p
- https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6&lt;/p&gt;
&lt;p&gt;Yet it was never patched...&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;This can, still, be used to escape the sandbox, one example (I&amp;#39;m sure there&amp;#39;s other ways as well), is via `console._stdout`/`console._stderr` (`NodeVM` with `console: &amp;#39;inherit&amp;#39;`, which is the default)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The prototype chain for `console._stdout`/`console._stderr` is:&lt;/p&gt;
&lt;p&gt;```
_stdout / _stderr
-&amp;gt; WriteStream (TTY only)
-&amp;gt; Socket
-&amp;gt; Duplex
-&amp;gt; Readable
-&amp;gt; Stream
-&amp;gt; EventEmitter
```&lt;/p&gt;
&lt;p&gt;`process` is an `EventEmitter`, and nothing stops us from writing things to `EventEmmiter.prototype`&lt;/p&gt;
&lt;p&gt;By overwriting `EventEmmiter.prototype.emit` with a function, and making `process` emit an event (e.g. `exit`, `unhandledRejection` etc.), we can execute code with `this` being `process`.&lt;/p&gt;
&lt;p&gt;This also bypasses `--disallow-code-generation-from-strings`, which blocks the &amp;#34;usual&amp;#34; escape of obtaining the host function constructor.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
const { NodeVM } = require(&amp;#34;vm2&amp;#34;);&lt;/p&gt;
&lt;p&gt;code = `
const gP = Buffer.call.call(__lookupGetter__,67,&amp;#39;__proto__&amp;#39;);&lt;/p&gt;
&lt;p&gt;// vm __proto__ getter
console.log(__lookupGetter__.call(0,&amp;#39;__proto__&amp;#39;).call(console._stderr)); // [Object…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;It being possible to obtain the host `__proto__` getter/setter, has been used in many reports:&lt;/p&gt;
&lt;p&gt;- https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq
- https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg
- https://github.com/patriksimek/vm2/security/advisories/GHSA-grj5-jjm8-h35p
- https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6&lt;/p&gt;
&lt;p&gt;Yet it was never patched...&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;This can, still, be used to escape the sandbox, one example (I&amp;#39;m sure there&amp;#39;s other ways as well), is via `console._stdout`/`console._stderr` (`NodeVM` with `console: &amp;#39;inherit&amp;#39;`, which is the default)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The prototype chain for `console._stdout`/`console._stderr` is:&lt;/p&gt;
&lt;p&gt;```
_stdout / _stderr
-&amp;gt; WriteStream (TTY only)
-&amp;gt; Socket
-&amp;gt; Duplex
-&amp;gt; Readable
-&amp;gt; Stream
-&amp;gt; EventEmitter
```&lt;/p&gt;
&lt;p&gt;`process` is an `EventEmitter`, and nothing stops us from writing things to `EventEmmiter.prototype`&lt;/p&gt;
&lt;p&gt;By overwriting `EventEmmiter.prototype.emit` with a function, and making `process` emit an event (e.g. `exit`, `unhandledRejection` etc.), we can execute code with `this` being `process`.&lt;/p&gt;
&lt;p&gt;This also bypasses `--disallow-code-generation-from-strings`, which blocks the &amp;#34;usual&amp;#34; escape of obtaining the host function constructor.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
const { NodeVM } = require(&amp;#34;vm2&amp;#34;);&lt;/p&gt;
&lt;p&gt;code = `
const gP = Buffer.call.call(__lookupGetter__,67,&amp;#39;__proto__&amp;#39;);&lt;/p&gt;
&lt;p&gt;// vm __proto__ getter
console.log(__lookupGetter__.call(0,&amp;#39;__proto__&amp;#39;).call(console._stderr)); // [Object…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-88hf-g992-jg85</guid>
    </item>
  </channel>
</rss>
