🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92960 vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92959 vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler t... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-71568 In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmct... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92958 vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92957 vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard r... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92956 vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compil... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92955 vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92954 vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92953 vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-w... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92952 vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92951 vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching ins... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92950 vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process.... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92949 vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92948 vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92947 vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92946 vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92945 vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92944 vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper ... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92942 vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call.... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92941 vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() an... | CRITICAL | ????? | ????? | NVD | 5 days ago |