<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 22:16:21 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14944</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14944</link>
      <description>bdu:2026-14944</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14944</guid>
    </item>
    <item>
      <title>EUVD-2026-371542</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371542</link>
      <description>EUVD-2026-371542</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371542</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92951</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92951</link>
      <description>&lt;p&gt;vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92951</guid>
    </item>
    <item>
      <title>GHSA-c48m-32m9-vx93 — vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c48m-32m9-vx93</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;vm2 is a sandbox library for isolating and executing untrusted JavaScript code inside a Node.js process. It can restrict access to built-in modules and external packages.&lt;/p&gt;
&lt;p&gt;When `NodeVM` enables an `external` allowlist together with a custom `resolve` callback, vm2 checks the requested package name with a non-exact match. For example, if the allowlist only permits `left-pad`, an attacker can still bypass the check with a colliding package name such as `evil-left-pad`, because it contains the allowlisted name.&lt;/p&gt;
&lt;p&gt;If the colliding package already exists in a host path resolvable by the custom resolver, or if the target application&amp;#39;s custom resolver / dependency-management workflow downloads the package and places it in a resolvable path, vm2 loads and executes that package in the host context. This lets sandboxed code bypass the module allowlist and may further lead to host code execution.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`NodeVM` supports `require.external` to configure which external npm packages sandboxed code may load. It also supports a custom resolver through `require.resolve`. This combination is commonly used in business plugin systems, user-script platforms, or sandbox execution environments: the application allows only a small set of trusted dependencies while using a custom resolver that points to the application&amp;#39;s own package directory.&lt;/p&gt;
&lt;p&gt;The vulnerability is in the allowlist pre-check logic before the custom resolver is called. vm2 generates a regular expression from the `e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;vm2 is a sandbox library for isolating and executing untrusted JavaScript code inside a Node.js process. It can restrict access to built-in modules and external packages.&lt;/p&gt;
&lt;p&gt;When `NodeVM` enables an `external` allowlist together with a custom `resolve` callback, vm2 checks the requested package name with a non-exact match. For example, if the allowlist only permits `left-pad`, an attacker can still bypass the check with a colliding package name such as `evil-left-pad`, because it contains the allowlisted name.&lt;/p&gt;
&lt;p&gt;If the colliding package already exists in a host path resolvable by the custom resolver, or if the target application&amp;#39;s custom resolver / dependency-management workflow downloads the package and places it in a resolvable path, vm2 loads and executes that package in the host context. This lets sandboxed code bypass the module allowlist and may further lead to host code execution.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`NodeVM` supports `require.external` to configure which external npm packages sandboxed code may load. It also supports a custom resolver through `require.resolve`. This combination is commonly used in business plugin systems, user-script platforms, or sandbox execution environments: the application allows only a small set of trusted dependencies while using a custom resolver that points to the application&amp;#39;s own package directory.&lt;/p&gt;
&lt;p&gt;The vulnerability is in the allowlist pre-check logic before the custom resolver is called. vm2 generates a regular expression from the `e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c48m-32m9-vx93</guid>
    </item>
    <item>
      <title>RHSA-2026:76788 — Red Hat Security Advisory: Red Hat Developer Hub 1.10.5 Plugin Catalog GA plugins release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:76788</link>
      <description>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass vm2: vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE vm2: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators urllib: urllib: Credential leakage via cross-origin redirects fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects multer: Multer: Denial of Service via file descriptor leak on aborted uploads multer: Multer: Denial of Service via crafted multipart field names jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions multer: Multer: Denial of Service via oversized array index in field names qs: qs: Denial of Service via improper validation in stringify function fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass vm2: vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE vm2: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators urllib: urllib: Credential leakage via cross-origin redirects fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects multer: Multer: Denial of Service via file descriptor leak on aborted uploads multer: Multer: Denial of Service via crafted multipart field names jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions multer: Multer: Denial of Service via oversized array index in field names qs: qs: Denial of Service via improper validation in stringify function fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:76788</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</guid>
    </item>
  </channel>
</rss>
