search
CVSS
Trends
- 1Medium-severity vulnerability flagged in Burst Statistics WordPress pluginโผ๐จ EUVD-2026-91950 ๐ Score: 4.3/10 (CVSS v3.1) ๐ฆ Product: Burst Statistics โ Simple WordPress Analytics (Google Analytics
A new vulnerability listing, EUVD-2026-91950, has been published for the Burst Statistics WordPress analytics plugin by vendor burstbv, an alternative to Google Analytics. The flaw carries a CVSS v3.1 score of 4.3 out of 10, indicating moderate severity. Administrators running the plugin on WordPress sites are advised to check for updates and patch promptly.
- 2WordPress app builder plugin hit by stored XSS flawโผ๐จ EUVD-2026-91951 ๐ Score: 5.4/10 (CVSS v3.1) ๐ฆ Product: WPMobile.App โ Android and iOS App Builder ๐ข Vendor: amauric ๐
A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App โ Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.
- 3WPC Product Options plugin hit by stored XSS flawโผ๐จ EUVD-2026-91952 ๐ Score: 7.2/10 (CVSS v3.1) ๐ฆ Product: WPC Product Options for WooCommerce ๐ข Vendor: WPClever ๐ Update
A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.
- 4Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3โCritical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a pa
A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.
- 5OpenTelemetry JavaScript instrumentation libraries flagged in new vulnerability advisoryโผ๐จ EUVD-2026-91788 ๐ Score: 5.8/10 (CVSS v3.1) ๐ฆ Product: instrumentation-cassandra-driver, instrumentation-pg, instrumen
A medium-severity vulnerability, EUVD-2026-91788, has been catalogued affecting several OpenTelemetry JavaScript Contrib instrumentation packages, including instrumentation-cassandra-driver, instrumentation-pg and instrumentation-tedious. The flaw carries a CVSS v3.1 score of 5.8 out of 10 and was updated on 2 October 2026. Security teams monitoring dependencies in Node.js applications are likely reviewing whether their projects use the affected OpenTelemetry packages.
- 6GitLab patches critical AI Gateway flaw allowing command executionโ๐ค GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access
GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.
- 7Low-severity directory traversal flaw patched in Trivy scannerโผ๐จ EUVD-2026-91789 ๐ Score: 2.5/10 (CVSS v3.1) ๐ฆ Product: trivy ๐ข Vendor: aquasec ๐ Updated: 2026-10-02 ๐ Trivy before 0.
A new vulnerability listing, EUVD-2026-91789, describes a directory traversal issue in Aqua Security's Trivy vulnerability scanner. Versions before 0.71.0 allow path traversal in Terraform filesystem functions that access pathnames above the scan root, with risk arising in misconfiguration scanning. The flaw carries a CVSS v3.1 score of 2.5, indicating low severity, and the advisory was updated on 2 October 2026. Users are advised to upgrade to 0.71.0 or later.
- 8High-severity SQL injection flaw reported in UTMStackโผ๐จ EUVD-2026-91790 ๐ Score: 8.7/10 (CVSS v3.1) ๐ฆ Product: UTMStack ๐ข Vendor: UTMStack ๐ Updated: 2026-10-02 ๐ UTMStack be
A newly catalogued vulnerability, EUVD-2026-91790, affects UTMStack versions before 11.2.16. The flaw is a SQL injection in the UtmAssetGroupService.searchQueryBuilder() component, allowing authenticated attackers to inject arbitrary SQL commands. The issue carries a CVSS v3.1 severity score of 8.7 out of 10, placing it in the high-severity range. The advisory record was updated on 2 October 2026, and users are expected to patch to version 11.2.16 or later.
- 9Newly published flaw hits AVEZ Electronics learning platformโผ๐จ EUVD-2026-91567 ๐ Score: 6.5/10 (CVSS v3.1) ๐ฆ Product: Learning Management System (LMS) ๐ข Vendor: AVEZ Electronics Com
A medium-severity missing authorization vulnerability, tracked as EUVD-2026-91567 and scored 6.5 out of 10 under CVSS v3.1, has been published for the Learning Management System from Turkish vendor AVEZ Electronics Communication Training and Consultancy Trade Inc. The advisory was updated on 2 October 2026. Missing authorization flaws can let users perform actions without proper permissions, so administrators of the LMS are being urged to review the advisory and apply any available fixes.
- 10High-severity infinite loop flaw reported in Apache Thrift Python bindingsโผ๐จ EUVD-2026-91568 ๐ Score: 8.2/10 (CVSS v3.1) ๐ฆ Product: Apache Thrift ๐ข Vendor: Apache Software Foundation ๐ Updated: 2
A vulnerability tracked as EUVD-2026-91568 has been disclosed in Apache Thrift, the Apache Software Foundation's cross-language RPC framework. The flaw, an infinite loop with an unreachable exit condition in the Python bindings, carries a CVSS v3.1 score of 8.2. Details on affected versions remain incomplete pending an update from the vendor.
- 11High-severity vulnerability disclosed in Apache Thrift Lua bindingsโผ๐จ EUVD-2026-91569 ๐ Score: 8.2/10 (CVSS v3.1) ๐ฆ Product: Apache Thrift ๐ข Vendor: Apache Software Foundation ๐ Updated: 2
A high-severity vulnerability, EUVD-2026-91569, has been catalogued affecting the Lua bindings of Apache Thrift, the cross-language RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.2 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling combined with inefficient algorithmic complexity, which could allow denial-of-service conditions. The advisory was updated on 2 October 2026.
- 12Critical vulnerability flagged in CISA's Malcolm network toolโ๐จ EUVD-2026-76738 ๐ Score: 9.2/10 (CVSS v3.1) ๐ฆ Product: Malcolm ๐ข Vendor: CISA ๐ Published: 2026-09-11 | Updated: 2026-
A high-severity vulnerability, EUVD-2026-76738, has been published for Malcolm, the open-source network traffic analysis toolkit distributed by CISA. The flaw, scored 9.2 out of 10 on the CVSS v3.1 scale, stems from an example environment-configuration file for a bundled inventory-management component that ships with a fixed, publicly known administrative password. The advisory was published on 11 September 2026 and updated on 2 October 2026.
- 13Malcolm vulnerability EUVD-2026-76736 rated medium severityโ๐จ EUVD-2026-76736 ๐ Score: 6.3/10 (CVSS v3.1) ๐ฆ Product: Malcolm ๐ข Vendor: CISA ๐ Published: 2026-09-11 | Updated: 2026-
A vulnerability tracked as EUVD-2026-76736 has been published for Malcolm, with a CVSS v3.1 score of 6.3 out of 10. According to the advisory, a prior update that raised a bundled HTTP client library to a version fixing known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version. The advisory was published on 11 September 2026 and updated on 2 October 2026.
- 14New vulnerability disclosed in Dynamic Web Lab Team Manager pluginโผ๐จ EUVD-2025-30618 ๐ Score: 5.3/10 (CVSS v3.1) ๐ฆ Product: Team Manager ๐ข Vendor: Dynamic Web Lab ๐ Published: 2025-09-22
A medium-severity vulnerability, tracked as EUVD-2025-30618, was published on 22 September 2025 affecting the Team Manager plugin for WordPress by vendor Dynamic Web Lab. The flaw, scored 5.3 out of 10 under CVSS v3.1, is a missing authorization issue that could let attackers exploit incorrectly configured access controls. An update to the entry was recorded on 2 October 2026.
- 15High-severity SQL injection flaw reported in HAVELSAN Sef chatbotโผ๐จ EUVD-2026-91329 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Sef - AI Chatbot Platform ๐ข Vendor: Havelsan Inc. ๐ Updated: 20
A SQL injection vulnerability, tracked as EUVD-2026-91329, has been disclosed in the Sef AI Chatbot Platform developed by Turkish defence and IT company HAVELSAN. The flaw carries a CVSS v3.1 score of 8.8, placing it in the high-severity range. SQL injection bugs of this kind can let attackers manipulate database queries, potentially exposing or altering sensitive data.
- 16Dell patches two CVSS 10.0 flaws in Kubernetes storage softwareโ๐ค Dell patches two max-severity (CVSS 10.0) flaws in Container Storage Modules (CSM) Authorization v2.4.0, which connect
Dell has released Container Storage Modules Authorization v2.4.0 to fix two maximum-severity flaws, both rated CVSS 10.0, in the software that connects Dell storage arrays to Kubernetes clusters. The bugs stem from missing authentication, allowing unauthenticated remote attackers to retrieve backend admin credentials across all tenants. Security teams running Dell storage with Kubernetes are urged to update immediately, as the flaws expose sensitive credentials without requiring valid accounts.
- 17Critical 10/10 vulnerability disclosed in Tenda routersโ๐จ EUVD-2026-91570 ๐ Score: 10.0/10 (CVSS v3.1) ๐ฆ Product: HG9, HG7, HG10 ๐ข Vendor: Tenda ๐ Updated: 2026-10-02 ๐ A secur
A maximum-severity security flaw, tracked as EUVD-2026-91570 with a CVSS score of 10.0, has been disclosed in Tenda HG7, HG9 and HG10 routers running the 300001138_en_xpon firmware. The vulnerability lies in the boaGetVar function in the /boaform/formLoopBack file. The advisory was updated on 2 October 2026, and security watchers are sharing the disclosure.
- 18Zitadel IAM flagged with D trust score over unpatched flawsโZitadel IAM carries a D trust score: 41 CVEs, max CVSS 9.3, and 97% left unpatched. Auth flaws (CWE-287) recur. Know you
Security analyst Hugo Valters reports that Zitadel, the open-source identity and access management platform, carries a D trust score based on 41 published CVEs, a maximum severity of 9.3, and 97% of vulnerabilities left unpatched. Authentication flaws classified under CWE-287 recur in the vendor's history. He urges organisations to assess their exposure before deploying the software.
- 19Cross-site scripting flaw found in Greek Open eClass platformโผ๐จ EUVD-2024-55777 ๐ Score: 5.4/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ Cross Site Scripting vulne
A cross-site scripting vulnerability, tracked as EUVD-2024-55777, has been disclosed in the Greek Universities Network (GUnet) Open eClass Platform version 3.15. The flaw, rated 5.4 out of 10 on the CVSS v3.1 scale, could let a remote attacker execute arbitrary code through user name fields. The advisory was published on 29 September and updated the following day.
- 20Keycloak Kerberos flaw lets network attackers hijack accountsโCVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take over
A newly disclosed vulnerability, CVE-2026-95503, affects Keycloak's Kerberos authentication and carries a CVSS score of 6.8. It remains unpatched. An attacker on the same network can spoof the Kerberos Key Distribution Center and take over user accounts. Security commentators urge administrators to isolate Kerberos traffic or stop using password authentication without SPNEGO protection until a fix is released.
- 21High-severity vulnerability disclosed in Apache Thrift Lua libraryโ๐จ EUVD-2026-91330 ๐ Score: 8.7/10 (CVSS v3.1) ๐ฆ Product: Apache Thrift ๐ข Vendor: Apache Software Foundation ๐ Updated: 2
A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.
- 22SSRF Vulnerability Disclosed in HAVELSAN Sef AI Chatbot Platformโ๐จ EUVD-2026-91323 ๐ Score: 4.9/10 (CVSS v3.1) ๐ฆ Product: Sef - AI Chatbot Platform ๐ข Vendor: Havelsan Inc. ๐ Updated: 20
A medium-severity vulnerability, tracked as EUVD-2026-91323 with a CVSS v3.1 score of 4.9, has been recorded for the Sef AI Chatbot Platform developed by Turkish defence technology company HAVELSAN Inc. The flaw is a server-side request forgery (SSRF) issue, which can allow an attacker to make the server send arbitrary requests. The advisory was updated on 2 October 2026; affected versions have not been fully detailed in the published record.
- 23High-severity unquoted service path flaw reported in Remote Mouseโ๐จ EUVD-2026-3018 ๐ Score: 8.5/10 (CVSS v3.1) ๐ฆ Product: Remote Mouse ๐ข Vendor: Remotemouse ๐ Published: 2026-01-15 | Upd
A vulnerability tracked as EUVD-2026-3018 has been published for Remote Mouse, the remote-control app by vendor Remotemouse. Version 4.002 contains an unquoted service path vulnerability, rated 8.5 out of 10 on the CVSS v3.1 scale, which can let a local attacker execute arbitrary code with elevated privileges. The entry was published on 15 January 2026 and updated on 1 October 2026. Users are advised to watch for a patched release from the vendor.
- 24Avada WordPress theme hit by reflected XSS vulnerabilityโ๐จ EUVD-2026-91174 ๐ Score: 6.1/10 (CVSS v3.1) ๐ฆ Product: Avada | Website Builder For WordPress & WooCommerce ๐ข Vendor: T
A medium-severity vulnerability, tracked as EUVD-2026-91174 with a CVSS score of 6.1, has been reported in Avada, the popular website builder theme for WordPress and WooCommerce from vendor ThemeFusion. The flaw is a reflected cross-site scripting issue, updated on 2026-10-02, allowing attackers to inject malicious scripts via crafted links. WordPress site owners using Avada are advised to update promptly.
- 25Discord libdave hit by critical vulnerability CVE-2026-104480โDiscord libdave CRITICAL vuln (CVE-2026-104480, CVSS 9.4): Affected versions 1.1.0 โ https:// radar.offseq.com/threat/cv
A critical vulnerability tracked as CVE-2026-104480, rated 9.4 on the CVSS scale, has been reported in Discord's libdave library, affecting version 1.1.0. The flaw is classified as CWE-390, detection of an error condition without action, meaning errors can occur without proper handling. Security researchers are circulating details of the issue and urging users and developers to watch for patches or updated releases.
- 26Critical LDAP injection flaw hits Red Hat Directory Server 11โRed Hat Directory Server 11: CVE-2026-86345 (CRITICAL, CVSS 9) allows on-path attackers to inject LDAP messages post-Sta
A critical vulnerability, CVE-2026-86345 with a CVSS score of 9, has been disclosed in Red Hat Directory Server 11. It allows on-path attackers to inject LDAP messages after StartTLS negotiation, potentially leading to authentication bypass. Security teams are being urged to restrict access to affected servers and follow Red Hat's advisory for remediation guidance.
- 27Medium-Severity Flaw Reported in FluentForm WordPress Pluginโผ๐จ EUVD-2026-90761 ๐ Score: 5.3/10 (CVSS v3.1) ๐ฆ Product: FluentForm ๐ข Vendor: WP ManageNinja LLC ๐ Updated: 2026-10-01 ๐
A vulnerability tracked as EUVD-2026-90761 has been published affecting FluentForm, the WordPress form plugin by WP ManageNinja LLC. The issue is classified as an Incorrect Behavior Order flaw with a CVSS v3.1 score of 5.3 out of 10, and can reportedly allow removal of important client functionality. Details were updated on 1 October 2026. Administrators running FluentForm are likely to check whether their installed version is affected and apply any available patch.
- 28High-severity XML flaw flagged in Apache Camel Quarkusโผ๐จ EUVD-2026-90762 ๐ Score: 8.6/10 (CVSS v3.1) ๐ฆ Product: Apache Camel Quarkus, Apache Camel Quarkus ๐ข Vendor: Apache Sof
A vulnerability tracked as EUVD-2026-90762 has been recorded for Apache Camel Quarkus, the Apache Software Foundation's Quarkus extensions for Camel. The flaw, rated 8.6 out of 10 under CVSS v3.1, involves improper restriction of XML external entity references in the XSLT support extension (camel-quarkus-support-xalan). Such issues can allow attackers to read files or make requests from affected systems. The record was updated on 1 October 2026, and security teams are being urged to check whether their deployments use the affected extension.
- 29Ultimate POS software flagged for stored cross-site scripting flawโ๐จ EUVD-2026-57170 ๐ Score: 4.8/10 (CVSS v3.1) ๐ฆ Product: Ultimate POS (Stock Management & Point of Sale) ๐ข Vendor: Ultim
A medium-severity vulnerability, tracked as EUVD-2026-57170, has been published for Ultimate POS, a stock management and point of sale application from vendor Ultimate Fosters. The flaw is a stored cross-site scripting issue, scored 4.8 out of 10 under CVSS v3.1. It was first published on 12 August 2026 and updated on 1 October 2026. Users of the software are advised to check for patches.
- 30Oracle PeopleSoft faces criticism over unpatched vulnerabilitiesโOracle PeopleSoft carries a D trust score. 44 CVEs, 33 rated critical or high, max CVSS 9.9 and 100% unpatched. Not one
Security researchers flag Oracle PeopleSoft with a D trust score, citing 44 known vulnerabilities, 33 of them rated critical or high severity, with a maximum CVSS score of 9.9 and none of them patched. None appear in CISA's Known Exploited Vulnerabilities catalog, but commentators argue that is little comfort when fixes are absent. The discussion stresses that patch prioritization matters, and criticism is mounting over Oracle's slow remediation of flaws in enterprise software still widely used by large organizations.
- 31encoded_id-rails vulnerability allows remote denial of service attacksโ๐จ EUVD-2023-2632 ๐ Score: 7.5/10 (CVSS v3.1) ๐ Published: 2024-01-04 | Updated: 2026-10-01 ๐ encoded_id-rails versions b
A security advisory tracked as EUVD-2023-2632 warns that encoded_id-rails versions before 1.0.0.beta2 contain an uncontrolled resource consumption flaw. A remote, unauthenticated attacker could exploit it to trigger a denial of service. The vulnerability carries a CVSS v3.1 score of 7.5 and was published on 4 January 2024, with the advisory most recently updated on 1 October 2026.
- 32New security vulnerability disclosed in Red Hat Enterprise Linux productsโผ๐จ EUVD-2023-24169 ๐ Score: 7.0/10 (CVSS v3.1) ๐ฆ Product: Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat V
A vulnerability tracked as EUVD-2023-24169 has been published affecting several Red Hat products, including Red Hat Enterprise Linux 8.6 and 8.8 Extended Update Support and Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. The flaw carries a CVSS v3.1 severity score of 7.0 out of 10, placing it in the high-severity range. Administrators running the affected versions are being advised to review the advisory and apply patches.
- 33pfSense vulnerability allows privilege injection, patch releasedโ๐จ EUVD-2026-70495 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: pfSense Plus, pfSense CE ๐ข Vendor: Netgate ๐ Published: 2026-09
A medium-severity vulnerability, tracked as EUVD-2026-70495 with a CVSS score of 5.1, affects Netgate's pfSense Plus before version 26.07 and pfSense CE before 2.9.0. The flaw lets authenticated users holding the Status: Monitoring privilege inject arbitrary content, potentially leading to further abuse. Netgate published the advisory on 3 September 2026 and updated it on 1 October; administrators are advised to upgrade.
- 34pfSense vulnerability EUVD-2026-70496 allows privilege injectionโ๐จ EUVD-2026-70496 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: pfSense Plus, pfSense CE ๐ข Vendor: Netgate ๐ Published: 2026-09
A medium-severity vulnerability, EUVD-2026-70496, has been published for Netgate's pfSense firewall software. Versions of pfSense Plus before 26.07 and pfSense CE before 2.9.0 allow authenticated users holding the Firewall: Rules: Edit privilege to inject data, according to the advisory rated 5.1 out of 10 under CVSS v3.1. The issue was published on 3 September 2026 and updated on 1 October. Administrators running affected versions are advised to update.
- 35Medium-severity vulnerability disclosed in pfSense firewall softwareโ๐จ EUVD-2026-70498 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: pfSense CE, pfSense Plus ๐ข Vendor: Netgate ๐ Published: 2026-09
A vulnerability tracked as EUVD-2026-70498 affects Netgate's pfSense Plus before 26.07 and pfSense CE before 2.9.0, carrying a CVSS v3.1 score of 5.1 out of 10. It allows authenticated users holding the Firewall: Schedules: Edit privilege to inject malicious content. Netgate published the advisory on 3 September 2026 and updated it on 1 October, and administrators of pfSense firewalls are being urged to update their installations.
- 36Kilo Code vulnerability lets local attackers run codeโผ๐จ EUVD-2026-89423 ๐ Score: 8.4/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ An issue in Kilo Code befo
A high-severity flaw tracked as EUVD-2026-89423 affects Kilo Code versions before v7.4.1, scoring 8.4 out of 10 under CVSS v3.1. The issue, published on 29 September 2026 and updated a day later, allows a local attacker to execute arbitrary code through the permission or allow-everything endpoint. Users are urged to update to v7.4.1 or later.
- 37Critical unpatched flaw reported in gray-matter parserโCVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patch
A newly published CVE, CVE-2026-78847, describes a critical remote code execution vulnerability in the gray-matter JavaScript front-matter parser. All versions are affected: code parsing JavaScript front matter uses eval() in lib/engines.js, letting attackers run arbitrary code. The flaw carries a CVSS score of 9.8 and no patch exists yet. Security commentators urge developers to avoid processing untrusted JavaScript front matter and to update as soon as a fix is released.
- 38Low-severity vm2 sandbox flaw disclosed under EUVD-2026-81594โ๐จ EUVD-2026-81594 ๐ Score: 2.3/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2: External
A new vulnerability entry, EUVD-2026-81594, has been published for the vm2 JavaScript sandbox library maintained by patriksimek. The flaw carries a low CVSS v3.1 score of 2.3 out of 10 and stems from the external module allowlist using a raw prefix test, meaning a sibling package sharing a name prefix is incorrectly treated as allowlisted. The entry was updated on 1 October 2026.
- 39Critical 10/10 vulnerability flagged in vm2 sandbox libraryโ๐จ EUVD-2026-81591 ๐ Score: 10.0/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 NodeVM c
A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.
- 40Critical vm2 sandbox escape vulnerability flagged in Node.jsโ๐จ EUVD-2026-81593 ๐ Score: 9.3/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 sandbox e
A high-severity vulnerability, EUVD-2026-81593, has been catalogued affecting vm2, the JavaScript sandbox library maintained by Patrik Simek. The flaw scores 9.3 out of 10 on CVSS v3.1 and allows a sandbox escape on Node.js 26 via a stale PromiseThenLookupChain protector. Security teams using vm2 to isolate untrusted code are being urged to review the advisory and assess exposure.