<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:49:30 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-26956 — vm2: WASM Sandbox Escape (Node 25 only)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-26956</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; patriksimek vm2, Red Hat Developer Hub, Red Hat Self-service automation portal 2&lt;/p&gt;
&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; patriksimek vm2, Red Hat Developer Hub, Red Hat Self-service automation portal 2&lt;/p&gt;
&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-26956</guid>
    </item>
  </channel>
</rss>
