<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: CVE Reports</title>
    <description>The latest articles on DEV Community by CVE Reports (@cverports).</description>
    <link>https://dev.to/cverports</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1959489%2F6e9f36b9-96a5-441a-a9b5-6993444f71d8.png</url>
      <title>DEV Community: CVE Reports</title>
      <link>https://dev.to/cverports</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/cverports"/>
    <language>en</language>
    <item>
      <title>CVE-2026-92957: CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Fri, 02 Oct 2026 04:30:31 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-92957-cve-2026-92957-sandbox-escape-and-remote-code-execution-in-vm2-via-node-prefix-inl</link>
      <guid>https://dev.to/cverports/cve-2026-92957-cve-2026-92957-sandbox-escape-and-remote-code-execution-in-vm2-via-node-prefix-inl</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-92957&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.9&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A vulnerability in the NodeVM component of the vm2 sandbox package through version 3.11.6 allows sandboxed code to bypass security policies restricting access to built-in modules. When a wildcard require policy is configured with negative deny entries using the 'node:' prefix (e.g., '-node:child_process'), the parser fails to recognize the exemption due to exact string comparison. As a result, the unmitigated module is registered, allowing sandboxed code to import the host child_process module and execute arbitrary system commands.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;vm2 fails to normalize the 'node:' prefix in negative builtin policy entries, allowing sandboxed code to load disallowed modules like 'child_process' and achieve remote code execution on the host.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-269&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v3.1 Score&lt;/strong&gt;: 9.9 (Critical)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v4.0 Score&lt;/strong&gt;: 9.4 (Critical)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00537 (43.14th percentile)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Maturity&lt;/strong&gt;: Proof of Concept&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CISA KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;vm2 sandbox environments running version 3.11.6 or earlier&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;vm2&lt;/strong&gt;: &amp;lt;= 3.11.6 (Fixed in: &lt;code&gt;3.11.7&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/patriksimek/vm2/commit/b0f50662dd499ff33544bb42387958c64711af1e" rel="noopener noreferrer"&gt;b0f5066&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;fix(GHSA-8686-vhfx-7r3j): normalize the node: prefix on negative builtin deny tokens&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight diff"&gt;&lt;code&gt;&lt;span class="p"&gt;@@ -12,3 +12,9 @@&lt;/span&gt;\n \t\t\t\tconst name = BUILTIN_MODULES[i];\n-\t\t\t\tif (builtins.indexOf(`-${name}`) === -1) {\n+\t\t\t\t// SECURITY (GHSA-8686-vhfx-7r3j): a negative deny token may be\n+\t\t\t\t// spelled with the `node:` URL prefix (`-node:child_process`),\n+\t\t\t\t// matching how `require()` accepts `node:`-prefixed specifiers.\n+\t\t\t\t// The exact-string match only recognized `-child_process`, so the\n+\t\t\t\t// `node:` spelling was a silent no-op and left the real host\n+\t\t\t\t// module exposed under `builtin: ['*']`. Match BOTH spellings.\n+\t\t\t\tif (builtins.indexOf(`-${name}`) === -1 &amp;amp;&amp;amp; builtins.indexOf(`-node:${name}`) === -1) {\n \t\t\t\t\taddDefaultBuiltin(res, name, hostRequire);\n
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade the vm2 package to version 3.11.7 or later to resolve the prefix normalization error.&lt;/li&gt;
&lt;li&gt;Avoid wildcard configurations with negative exclusions. Instead, explicitly define a strict allowlist containing only the minimal set of required modules.&lt;/li&gt;
&lt;li&gt;Migrate existing sandboxed execution flows away from vm2 to alternative isolation boundaries such as WebAssembly runtimes or containerized processes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify all projects and configurations utilizing the vm2 package.&lt;/li&gt;
&lt;li&gt;Review configuration files initializing NodeVM, locating any occurrences of wildcard require policies containing negative deny tokens (e.g., 'builtin: ["*", "-node:..."]').&lt;/li&gt;
&lt;li&gt;Update package.json dependencies to target 'vm2': '^3.11.7'. Run npm install or yarn install to apply the patch.&lt;/li&gt;
&lt;li&gt;If upgrading is not immediately possible, rewrite the NodeVM options block to explicitly allow only specific safe built-in libraries (e.g., builtin: ['path', 'url']) and avoid using wildcard rules combined with exemptions.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-8686-vhfx-7r3j" rel="noopener noreferrer"&gt;GitHub Security Advisory GHSA-8686-vhfx-7r3j&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/vm2-before-3.11.7-authentication-bypass-via-node-prefix" rel="noopener noreferrer"&gt;VulnCheck Advisory for vm2 Node Prefix Bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92957.json" rel="noopener noreferrer"&gt;CVE Record JSON Data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-92957" rel="noopener noreferrer"&gt;NVD CVE-2026-92957 Detail&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-92957" rel="noopener noreferrer"&gt;CVE.org CVE-2026-92957 Record&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/commit/b0f50662dd499ff33544bb42387958c64711af1e" rel="noopener noreferrer"&gt;Fix Commit b0f5066&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-92957" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-92957 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-92958: CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Fri, 02 Oct 2026 03:30:30 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-92958-cve-2026-92958-built-in-module-denylist-bypass-via-fspromises-in-vm2-nodevm-4k86</link>
      <guid>https://dev.to/cverports/cve-2026-92958-cve-2026-92958-built-in-module-denylist-bypass-via-fspromises-in-vm2-nodevm-4k86</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-92958&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 8.5&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;CVE-2026-92958 is a high-severity sandbox escape and denylist bypass vulnerability within the NodeVM subsystem of the vm2 sandboxing library. When configuring wildcards with negative deny entries, exact-string matches fail to block subpaths like fs/promises. Sandboxed code can import these subpaths to bypass isolation and execute arbitrary filesystem operations on the host.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;A denylist bypass vulnerability in vm2 &amp;lt;= 3.11.6 allows sandboxed code to bypass security rules by importing unblocked subpath modules like fs/promises, enabling arbitrary write access to the host filesystem.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-269&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v3.1&lt;/strong&gt;: 8.5&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00384&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: PoC&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CISA KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;vm2 Node.js sandboxing library&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;vm2&lt;/strong&gt;: &amp;lt;= 3.11.6 (Fixed in: &lt;code&gt;3.11.7&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/patriksimek/vm2/commit/59d35f68e52a9bd229a8a72bcd9274bd4cec2bc5" rel="noopener noreferrer"&gt;59d35f6&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Fix builtin-module denylist bypass in NodeVM&lt;/p&gt;

&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-6rh5-qq4q-97xh" rel="noopener noreferrer"&gt;GitHub Security Advisory&lt;/a&gt;: No description&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade the vm2 package to version 3.11.7 or higher.&lt;/li&gt;
&lt;li&gt;Manually list all subpath modules in the deny list of NodeVM if upgrading is not immediately possible.&lt;/li&gt;
&lt;li&gt;Migrate away from the deprecated vm2 library to stronger isolation runtimes such as WebAssembly or Docker containers.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Run 'npm install &lt;a href="mailto:vm2@3.11.7"&gt;vm2@3.11.7&lt;/a&gt;' to apply the update.&lt;/li&gt;
&lt;li&gt;Audit existing NodeVM initialization configurations to ensure negative rules include both parent and subpath modules.&lt;/li&gt;
&lt;li&gt;Validate the sandbox constraints using automated test suites.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-6rh5-qq4q-97xh" rel="noopener noreferrer"&gt;https://github.com/patriksimek/vm2/security/advisories/GHSA-6rh5-qq4q-97xh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/commit/59d35f68e52a9bd229a8a72bcd9274bd4cec2bc5" rel="noopener noreferrer"&gt;https://github.com/patriksimek/vm2/commit/59d35f68e52a9bd229a8a72bcd9274bd4cec2bc5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/releases/tag/v3.11.7" rel="noopener noreferrer"&gt;https://github.com/patriksimek/vm2/releases/tag/v3.11.7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/vm2-before-3.11.7-denylist-bypass-via-fs-promises" rel="noopener noreferrer"&gt;https://www.vulncheck.com/advisories/vm2-before-3.11.7-denylist-bypass-via-fs-promises&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-92958" rel="noopener noreferrer"&gt;https://www.cve.org/CVERecord?id=CVE-2026-92958&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-92958" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-92958&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-92958" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-92958 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-92951: CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Fri, 02 Oct 2026 02:31:02 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-92951-cve-2026-92951-sandbox-escape-via-external-package-allowlist-bypass-in-vm2-1l33</link>
      <guid>https://dev.to/cverports/cve-2026-92951-cve-2026-92951-sandbox-escape-via-external-package-allowlist-bypass-in-vm2-1l33</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-92951&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.9&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An incorrect authorization and directory traversal vulnerability in the vm2 library before version 3.11.7 allows remote attackers to bypass the sandbox's external package allowlist. This flaw permits sandboxed code to resolve and execute arbitrary packages available on the host filesystem under host privileges, leading to unauthenticated sandbox escape and host code execution.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;A flaw in vm2's bare-specifier matcher allowlist check allows sandbox escape. It uses unanchored substring matching and fails to filter directory traversal sequences, allowing untrusted code to load and execute arbitrary host packages with full authority.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-706, CWE-863, CWE-829&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v3.1 Score&lt;/strong&gt;: 9.9 (Critical)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: Proof of Concept (PoC) documented in test suite&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CISA KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00539&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impact&lt;/strong&gt;: Complete Sandbox Escape &amp;amp; Host Code Execution&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Applications executing untrusted code using vm2 NodeVM configurations&lt;/li&gt;
&lt;li&gt;Multi-tenant plugin hosting systems relying on vm2 external module allowlists&lt;/li&gt;
&lt;li&gt;Serverless runtimes and webhooks using deprecated vm2 sandbox instances&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;vm2&lt;/strong&gt;: &amp;lt; 3.11.7 (Fixed in: &lt;code&gt;3.11.7&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/patriksimek/vm2/commit/ab4ee7d803e8c80155e9eb3672226bddbca4aa9c" rel="noopener noreferrer"&gt;ab4ee7d&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Security fix for external-package allowlist bypass in LegacyResolver&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight diff"&gt;&lt;code&gt;&lt;span class="p"&gt;@@ -109,7 +109,16 @@&lt;/span&gt;\n\t\tthis.externalCache = externals.map(pattern =&amp;gt; new RegExp('^(?:' + makeExternalMatcherRegex(pattern) + ')(?:[\\\\/].*)?$'));\n@@ -184,6 +193,18 @@\n\t\t\tif (x.split(/[\\/]/).indexOf('..') !== -1) return undefined;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-c48m-32m9-vx93" rel="noopener noreferrer"&gt;GitHub security advisory test cases&lt;/a&gt;: Functional unit tests demonstrating unanchored regex match and path traversal validation bypasses&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade vm2 to version 3.11.7 or later where the boundaries of external matchers are strictly anchored and traversal sequences are rejected.&lt;/li&gt;
&lt;li&gt;Migrate to robust isolation mechanisms such as isolates (e.g., isolated-vm), WebAssembly (WASM) runtimes, or containerized execution.&lt;/li&gt;
&lt;li&gt;Implement strong OS-level sandboxing (such as AppArmor, gVisor, or Docker with non-root configurations) to limit the damage of an escape.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify all direct and transitive dependencies on the 'vm2' package in your project's lockfile.&lt;/li&gt;
&lt;li&gt;Update the package.json dependency for 'vm2' to '^3.11.7'.&lt;/li&gt;
&lt;li&gt;Run your package manager's installation command (e.g., 'npm install' or 'yarn install') to apply the patch.&lt;/li&gt;
&lt;li&gt;Verify that the compiled regex mappings inside 'lib/resolver-compat.js' match the anchored patterns.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-c48m-32m9-vx93" rel="noopener noreferrer"&gt;GHSA-c48m-32m9-vx93&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-via-custom-resolver" rel="noopener noreferrer"&gt;VulnCheck Security Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-92951" rel="noopener noreferrer"&gt;NVD - CVE-2026-92951&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-92951" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-92951 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-92940: CVE-2026-92940: Host-Realm Credential Exposure and Socket Hijacking via globalAgent in vm2</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Fri, 02 Oct 2026 01:30:30 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-92940-cve-2026-92940-host-realm-credential-exposure-and-socket-hijacking-via-globalagent-51ci</link>
      <guid>https://dev.to/cverports/cve-2026-92940-cve-2026-92940-host-realm-credential-exposure-and-socket-hijacking-via-globalagent-51ci</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-92940: Host-Realm Credential Exposure and Socket Hijacking via globalAgent in vm2
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-92940&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 10.0&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A critical vulnerability in the Node.js sandbox library vm2 allows sandboxed code to retrieve the process-wide http.globalAgent and https.globalAgent singletons. By attaching event listeners to these host-realm emitters, sandboxed code can intercept host-realm network requests, capturing sensitive Authorization headers and hijacking active TLSSocket streams.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;A sandbox escape in vm2 (versions 3.11.3 to 3.11.6) allows untrusted code to access and hook the host process-wide http/https globalAgent. This enables unauthenticated attackers to steal sensitive headers (like Bearer tokens) and hijack active sockets during unrelated host-realm requests.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-668: Exposure of Resource to Wrong Sphere&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network (AV:N)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v3.1 Score&lt;/strong&gt;: 10.0 (Critical)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00474 (Percentile: 38.70%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impact&lt;/strong&gt;: Host Credential Disclosure &amp;amp; Transport Socket Hijacking&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: Proof-of-Concept (PoC) available via official regression test suite&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CISA KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;vm2 (npm package)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;vm2&lt;/strong&gt;: &amp;gt;= 3.11.3, &amp;lt;= 3.11.6 (Fixed in: &lt;code&gt;3.11.7&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483daa" rel="noopener noreferrer"&gt;aa146a7&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Implement member-level sanitization for built-in HTTP and HTTPS agents to prevent globalAgent exposure inside the sandbox context.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight diff"&gt;&lt;code&gt;&lt;span class="gd"&gt;--- a/lib/builtin.js
&lt;/span&gt;&lt;span class="gi"&gt;+++ b/lib/builtin.js
+// Adds sanitization and overwrites request/get to use sandboxed agents
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-h85j-hv3c-qfgq" rel="noopener noreferrer"&gt;GitHub Security Advisory&lt;/a&gt;: Details the vulnerability report, the architectural mechanism of the escape, and provides the reproduction script used as verification.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade vm2 to version 3.11.7 or newer to apply member-level neutralization on built-in HTTP/HTTPS modules.&lt;/li&gt;
&lt;li&gt;Disable the 'http' and 'https' built-in modules inside the NodeVM configuration settings to remove the attack vector entirely.&lt;/li&gt;
&lt;li&gt;Implement outbound network requests outside of the sandbox boundary using a strictly validated custom host-realm API rather than exposing native raw network modules.&lt;/li&gt;
&lt;li&gt;Transition application architectures away from vm2 to modern isolated runtimes, such as isolated-vm or VM containers.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Locate and audit package.json and project lockfiles for vm2 references within versions 3.11.3 and 3.11.6.&lt;/li&gt;
&lt;li&gt;Run 'npm install &lt;a href="mailto:vm2@3.11.7"&gt;vm2@3.11.7&lt;/a&gt;' or 'yarn upgrade &lt;a href="mailto:vm2@3.11.7"&gt;vm2@3.11.7&lt;/a&gt;' to deploy the patched library version.&lt;/li&gt;
&lt;li&gt;Review initialization scripts of NodeVM to ensure that 'http' and 'https' are absent from the require.builtin array.&lt;/li&gt;
&lt;li&gt;Validate the fix by executing the official regression test to ensure host globalAgent is no longer reachable from the sandbox environment.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-h85j-hv3c-qfgq" rel="noopener noreferrer"&gt;GHSA-h85j-hv3c-qfgq Security Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-https-credential-exposure-via-globalagent" rel="noopener noreferrer"&gt;VulnCheck Vulnerability Report&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483daa" rel="noopener noreferrer"&gt;Official Patch Commit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/releases/tag/v3.11.7" rel="noopener noreferrer"&gt;vm2 v3.11.7 Release Tag&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-92940" rel="noopener noreferrer"&gt;NVD CVE-2026-92940 Details&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-92940" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-92940 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-92950: CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Fri, 02 Oct 2026 00:31:31 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-92950-cve-2026-92950-sandbox-escape-vulnerability-in-vm2-cli-5g43</link>
      <guid>https://dev.to/cverports/cve-2026-92950-cve-2026-92950-sandbox-escape-vulnerability-in-vm2-cli-5g43</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-92950&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.3&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;CVE-2026-92950 (GHSA-jxxv-8r27-vm4p) is a critical sandbox escape vulnerability in the command-line interface of the vm2 library prior to version 3.11.7. The flaw allows untrusted scripts to bypass sandbox constraints and execute arbitrary system commands with the privileges of the host process by exploiting insecure default configurations of the module resolver.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;A design flaw in the vm2 CLI tool permits sandboxed code to load local files in the host execution realm, resulting in a complete sandbox escape and unauthenticated arbitrary command execution.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-453 (Insecure Default Variable Initialization)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Local&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v4.0 Score&lt;/strong&gt;: 9.3 (Critical)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00197 (8.53rd Percentile)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: Proof-of-Concept Publicly Available&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;vm2 CLI (npm package)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;vm2&lt;/strong&gt;: &amp;lt; 3.11.7 (Fixed in: &lt;code&gt;3.11.7&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/patriksimek/vm2/commit/903017c8a1eae9aba947ec854468b48155e79f86" rel="noopener noreferrer"&gt;903017c&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Fix escape when running vm2 command line tool with require.root and require.context limits&lt;/p&gt;

&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-jxxv-8r27-vm4p" rel="noopener noreferrer"&gt;GitHub Security Advisory&lt;/a&gt;: GHSA advisory describing the insecure default options and reproduction payload.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade the vm2 library to version 3.11.7 or higher.&lt;/li&gt;
&lt;li&gt;Configure NodeVM instances with a explicitly specified require.root directory.&lt;/li&gt;
&lt;li&gt;Set require.context to 'sandbox' to enforce compilation boundaries within the VM.&lt;/li&gt;
&lt;li&gt;Migrate to runtime containerization or process-level isolation models.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify all global and local installations of the vm2 npm package.&lt;/li&gt;
&lt;li&gt;Run 'npm install &lt;a href="mailto:vm2@3.11.7"&gt;vm2@3.11.7&lt;/a&gt;' or update package.json dependencies to target &amp;gt;=3.11.7.&lt;/li&gt;
&lt;li&gt;Audit custom NodeVM configuration code to verify that require.external is not used without require.root.&lt;/li&gt;
&lt;li&gt;Validate remediation by testing custom modules against the self-require exploit pattern.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-jxxv-8r27-vm4p" rel="noopener noreferrer"&gt;GitHub Security Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/vm2-before-3.11.7-sandbox-escape-via-cli-require" rel="noopener noreferrer"&gt;VulnCheck Security Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-92950" rel="noopener noreferrer"&gt;CVE Record&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-92950" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-92950 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-92948: CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Thu, 01 Oct 2026 23:30:31 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-92948-cve-2026-92948-sandbox-escape-and-remote-code-execution-in-vm2-via-nodetest-4mlp</link>
      <guid>https://dev.to/cverports/cve-2026-92948-cve-2026-92948-sandbox-escape-and-remote-code-execution-in-vm2-via-nodetest-4mlp</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-92948&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.9&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;CVE-2026-92948 is a critical sandbox escape vulnerability in the vm2 library affecting versions 3.9.6 through 3.11.6 when executed on Node.js 24 and newer. The vulnerability allows an attacker to bypass built-in module blocking defenses by double-prefixing a restricted module name (such as node:node:test). This permits the loading of the node:test module, whose test runner execution can be leveraged to execute arbitrary shell commands outside the VM sandbox.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;A critical sandbox escape in vm2 (versions &amp;gt;=3.9.6 to &amp;lt;=3.11.6) allows attackers to execute arbitrary system commands on the host by leveraging a prefix-stripping flaw to import the 'node:test' core module on Node.js 24+.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-693&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS Score&lt;/strong&gt;: 9.9 (Critical)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00654&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impact&lt;/strong&gt;: Complete Sandbox Escape &amp;amp; Host Remote Code Execution&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: Proof-of-Concept Available&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;vm2 (npm package) running on Node.js 24+&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;vm2&lt;/strong&gt;: &amp;gt;= 3.9.6, &amp;lt;= 3.11.6 (Fixed in: &lt;code&gt;3.11.7&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/patriksimek/vm2/commit/415339f698f0d52d3c5ad358b12b79c8072d5b4b" rel="noopener noreferrer"&gt;415339f&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Fix GHSA-qhwx-74w5-xhxq: sanitize input and block dangerous builtins recursively&lt;/p&gt;

&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq" rel="noopener noreferrer"&gt;GitHub Security Advisory&lt;/a&gt;: Vulnerability disclosure detailing the node:test sandbox escape exploit vector.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade vm2 to version 3.11.7 or later to apply recursive prefix validation.&lt;/li&gt;
&lt;li&gt;Explicitly remove wildcard ('*') and 'node:test' from the VM's builtin allowlist.&lt;/li&gt;
&lt;li&gt;Migrate to isolated-vm to use secure V8 isolate-based boundaries instead of vm2.&lt;/li&gt;
&lt;li&gt;Execute untrusted code within secure container environments (e.g., Docker, gVisor) to limit host system exposure.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify all microservices and dependencies utilizing the vm2 npm package.&lt;/li&gt;
&lt;li&gt;Update package.json to specify vm2 version 3.11.7 or newer, then execute 'npm install'.&lt;/li&gt;
&lt;li&gt;Inspect NodeVM configurations to ensure the 'builtin' array does not contain '*' or 'node:test'.&lt;/li&gt;
&lt;li&gt;Plan the deprecation of vm2 in favor of a containerized execution model or isolated-vm.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq" rel="noopener noreferrer"&gt;GHSA-qhwx-74w5-xhxq&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/vm2-3.9.6-through-3.11.5-sandbox-escape-via-node-test" rel="noopener noreferrer"&gt;VulnCheck Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/releases/tag/v3.11.7" rel="noopener noreferrer"&gt;vm2 v3.11.7 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-92948" rel="noopener noreferrer"&gt;NVD CVE-2026-92948 Detail&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-92948" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-92948 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-92952: CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Thu, 01 Oct 2026 22:30:29 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-92952-cve-2026-92952-sandbox-escape-and-state-corruption-in-vm2-via-nodejs-internal-4kmo</link>
      <guid>https://dev.to/cverports/cve-2026-92952-cve-2026-92952-sandbox-escape-and-state-corruption-in-vm2-via-nodejs-internal-4kmo</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-92952&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 8.9&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A high-severity sandbox escape and state corruption vulnerability exists in the vm2 library (versions 3.11.4 through 3.11.6). The vulnerability is caused by an incomplete blocklist of Node.js-internal registered symbols crossing the sandbox-host bridge boundary. Specifically, the filters in &lt;code&gt;lib/setup-sandbox.js&lt;/code&gt; and write traps in &lt;code&gt;lib/bridge.js&lt;/code&gt; omitted the symbols &lt;code&gt;nodejs.stream.disturbed&lt;/code&gt; and &lt;code&gt;nodejs.stream.errored&lt;/code&gt;, allowing untrusted code within the sandbox to corrupt host-realm stream state checks.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;An incomplete blocklist of Node.js-internal symbols in vm2 (3.11.4-3.11.6) allows sandboxed code to access host-realm stream symbols, corrupt stream state accessors on the host, and bypass security gates.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-669&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Adjacent/Remote dependent on application exposure&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v4.0 Score&lt;/strong&gt;: 8.9&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00461 (Percentile: 37.62%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impact&lt;/strong&gt;: High Integrity Impact / Sandbox Escape&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: PoC / Non-weaponized&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;vm2 library (versions 3.11.4 through 3.11.6) running on Node.js runtimes containing web streams&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;vm2&lt;/strong&gt;: &amp;gt;= 3.11.4, &amp;lt;= 3.11.6 (Fixed in: &lt;code&gt;3.11.7&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/patriksimek/vm2/commit/a45444d5abbdfa59055528f584df5f21cc7c42da" rel="noopener noreferrer"&gt;a45444d&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Fix dangerous-symbol filtering bypass (GHSA-jf8q-945g-9q4c) by utilizing a namespace-based catch-all check.&lt;/p&gt;

&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-jf8q-945g-9q4c" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;: The advisory contains structural details and unit test definitions showing how the bypass behaves on modern Node.js versions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade vm2 dependency to version 3.11.7 immediately to apply namespace symbol filtering.&lt;/li&gt;
&lt;li&gt;Migrate to process-isolated script execution architectures such as isolated-vm or isolated container sandboxes.&lt;/li&gt;
&lt;li&gt;Implement strong input validation to prevent user-supplied script execution within single-isolate virtual machines.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify all direct and transitive dependencies on vm2 in package.json files.&lt;/li&gt;
&lt;li&gt;Update the vm2 dependency to version 3.11.7 using npm install &lt;a href="mailto:vm2@3.11.7"&gt;vm2@3.11.7&lt;/a&gt; or yarn upgrade &lt;a href="mailto:vm2@3.11.7"&gt;vm2@3.11.7&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Validate host application behaviors by executing unit tests on stream handling mechanisms.&lt;/li&gt;
&lt;li&gt;Plan and execute an architecture migration to replace deprecated vm2 isolates with subprocess boundaries.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-92952" rel="noopener noreferrer"&gt;NVD Record for CVE-2026-92952&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-jf8q-945g-9q4c" rel="noopener noreferrer"&gt;GitHub Security Advisory GHSA-jf8q-945g-9q4c&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patriksimek/vm2/releases/tag/v3.11.7" rel="noopener noreferrer"&gt;vm2 v3.11.7 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/vm2-3.11.4-through-3.11.6-sandbox-symbol-filtering-bypass" rel="noopener noreferrer"&gt;VulnCheck Advisory Portal&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-92952" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-92952 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-73607: CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Thu, 01 Oct 2026 21:30:31 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-73607-cve-2026-73607-missing-authorization-in-siyuan-apistoragegetoutlinestorage-5hbn</link>
      <guid>https://dev.to/cverports/cve-2026-73607-cve-2026-73607-missing-authorization-in-siyuan-apistoragegetoutlinestorage-5hbn</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-73607&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 5.8&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An architectural evaluation of CVE-2026-73607 in the SiYuan personal knowledge management system. This technical advisory details a Missing Authorization (CWE-862) vulnerability in the Go-based backend kernel, specifically within the outline storage API endpoint. Under certain configurations, authenticated low-privilege users can query metadata, heading structures, and block hierarchies of restricted documents.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;A Broken Object Level Authorization (BOLA) vulnerability in SiYuan prior to v3.7.4 allows authenticated users to extract document outlines and structural metadata of unauthorized notes via the &lt;code&gt;/api/storage/getOutlineStorage&lt;/code&gt; API endpoint.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-862 (Missing Authorization)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network (AV:N)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v3.1 / v4.0&lt;/strong&gt;: 5.8 (Medium) / 6.9 (Medium)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00325 (Percentile: 23.20%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impact&lt;/strong&gt;: Information Disclosure (Confidentiality: Low)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: PoC Available / No Active Exploitation&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;SiYuan Personal Knowledge Management System&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SiYuan&lt;/strong&gt;: &amp;gt;= 0, &amp;lt; 3.7.4 (Fixed in: &lt;code&gt;3.7.4&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade SiYuan to v3.7.4 or later&lt;/li&gt;
&lt;li&gt;Implement network-level segmentation to restrict API access&lt;/li&gt;
&lt;li&gt;Restrict user creation and guest access on server-mode instances&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Verify the currently running version of the SiYuan kernel by inspecting the application logs or interface settings.&lt;/li&gt;
&lt;li&gt;Download the latest stable release (v3.8.0 or newer) from the official repository.&lt;/li&gt;
&lt;li&gt;Replace the old executable or container image with the updated version.&lt;/li&gt;
&lt;li&gt;Restart the SiYuan service and monitor authentication logs for standard API requests.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan/security/advisories/GHSA-53fp-9jmv-227g" rel="noopener noreferrer"&gt;GitHub Security Advisory (GHSA-53fp-9jmv-227g)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getoutlinestorage" rel="noopener noreferrer"&gt;VulnCheck Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-73607" rel="noopener noreferrer"&gt;CVE Record&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0" rel="noopener noreferrer"&gt;Official Patch Release Tag (v3.8.0)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-73607" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-73607 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-73609: CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Thu, 01 Oct 2026 20:30:31 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-73609-cve-2026-73609-missing-authorization-in-siyuan-note-getbookmarklabels-endpoint-52ph</link>
      <guid>https://dev.to/cverports/cve-2026-73609-cve-2026-73609-missing-authorization-in-siyuan-note-getbookmarklabels-endpoint-52ph</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-73609&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 5.8&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An information disclosure vulnerability (CWE-862) in the SiYuan Note platform before version v3.7.4 allows anonymous or unprivileged readers to obtain a complete list of bookmark labels globally across all workspaces and notebooks by querying the &lt;code&gt;/api/attr/getBookmarkLabels&lt;/code&gt; API endpoint.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;Missing authorization checks on the &lt;code&gt;/api/attr/getBookmarkLabels&lt;/code&gt; endpoint in SiYuan Note allow unauthenticated or unprivileged users to query and retrieve all bookmark labels across the entire workspace, exposing confidential project names, structures, and metadata.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-862&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v3.1&lt;/strong&gt;: 5.8&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v4.0&lt;/strong&gt;: 6.9&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00325 (0.33%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: Conceptual Proof of Concept&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;SiYuan Note&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SiYuan&lt;/strong&gt;: &amp;lt; v3.7.4 (Fixed in: &lt;code&gt;v3.7.4&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Code Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Commit: &lt;a href="https://github.com/siyuan-note/siyuan/commit/251596fc0de2f9528c00c224252fd073a99973f4" rel="noopener noreferrer"&gt;251596f&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Enforce publish access controls for getBookmarkLabels&lt;/p&gt;

&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getbookmarklabels" rel="noopener noreferrer"&gt;VulnCheck&lt;/a&gt;: Information disclosure advisory highlighting the getBookmarkLabels endpoint vulnerability.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade SiYuan Note to version v3.7.4 or later&lt;/li&gt;
&lt;li&gt;Bind Siyuan Note server strictly to localhost loopback interface (127.0.0.1)&lt;/li&gt;
&lt;li&gt;Restrict endpoint access using Nginx or other reverse proxies to filter path /api/attr/getBookmarkLabels&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify the current running version of Siyuan Note.&lt;/li&gt;
&lt;li&gt;Download the updated version (v3.7.4 or later) from the official GitHub repository.&lt;/li&gt;
&lt;li&gt;Apply the update and restart the server.&lt;/li&gt;
&lt;li&gt;Validate the fix by attempting an unauthenticated POST request to /api/attr/getBookmarkLabels.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-73609" rel="noopener noreferrer"&gt;NVD Record&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4ph-9xwf-wcj4" rel="noopener noreferrer"&gt;GitHub Security Advisory (GHSA)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-73609" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-73609 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-76504: CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Thu, 01 Oct 2026 17:31:32 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-76504-cve-2026-76504-unauthenticated-authentication-bypass-in-cisco-catalyst-sd-wan-4m7c</link>
      <guid>https://dev.to/cverports/cve-2026-76504-cve-2026-76504-unauthenticated-authentication-bypass-in-cisco-catalyst-sd-wan-4m7c</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-76504&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.8&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;CVE-2026-76504 is a critical vulnerability in the web-based management console of Cisco Catalyst SD-WAN Manager. Due to improper normalization and handling of hex/percent-encoded sequences (CWE-177) within incoming request URIs, remote, unauthenticated attackers can bypass administrative authentication controls. Successful exploitation permits full remote administrative command execution on the SD-WAN management plane, threatening the integrity and availability of the managed network fabric.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;An unauthenticated remote authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allows attackers to perform administrative actions with root-level privileges by exploiting inconsistency in URI hex/percent-encoding handling across web application layers.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: ACTIVE
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-177 (Improper Handling of URL Encoding)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network (AV:N)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v3.1 Score&lt;/strong&gt;: 9.8&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: active&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CISA KEV Listed&lt;/strong&gt;: Yes (Added September 30, 2026)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impact&lt;/strong&gt;: Complete administrative compromise of SD-WAN management interface&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Cisco Catalyst SD-WAN Manager (formerly vManage)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;: &amp;lt; 20.9.10.1 (Fixed in: &lt;code&gt;20.9.10.1&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;: &amp;gt;= 20.12.0.0, &amp;lt; 20.12.8.2 (Fixed in: &lt;code&gt;20.12.8.2&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;: &amp;gt;= 20.15.0.0, &amp;lt; 20.15.6.1 (Fixed in: &lt;code&gt;20.15.6.1&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;: &amp;gt;= 20.18.0.0, &amp;lt; 20.18.4.1 (Fixed in: &lt;code&gt;20.18.4.1&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;: &amp;gt;= 26.1.0.0, &amp;lt; 26.1.2.1 (Fixed in: &lt;code&gt;26.1.2.1&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;: &amp;gt;= 26.2.0.0, &amp;lt; 26.2.1 (Fixed in: &lt;code&gt;26.2.1&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept" rel="noopener noreferrer"&gt;ShadowForge Cyber PoC Repository&lt;/a&gt;: Exploit verification script and public vulnerability analysis framework detailing target analysis features and command-line execution structures.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;De-expose Cisco Catalyst SD-WAN Manager management interfaces from the public internet.&lt;/li&gt;
&lt;li&gt;Implement restrictive local network and firewall Access Control Lists (ACLs) to allow traffic only from designated, trusted administrative hosts.&lt;/li&gt;
&lt;li&gt;Enforce authentication protocols at the network perimeter, such as requiring VPN or Multi-Factor authenticated jump servers to access administrative zones.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify the current software generation of all deployed Catalyst SD-WAN Manager instances.&lt;/li&gt;
&lt;li&gt;Cross-reference the running version against the fixed release matrix to determine the correct target firmware path.&lt;/li&gt;
&lt;li&gt;Schedule emergency maintenance windows to deploy the updated software versions.&lt;/li&gt;
&lt;li&gt;Verify that the web interface is inaccessible via paths containing double-escaped or percent-encoded traversal indicators.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU" rel="noopener noreferrer"&gt;Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504" rel="noopener noreferrer"&gt;CISA KEV Catalog Reference for CVE-2026-76504&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-76504" rel="noopener noreferrer"&gt;CVE-2026-76504 on CVE.org&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76504" rel="noopener noreferrer"&gt;NVD Vulnerability Details for CVE-2026-76504&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept" rel="noopener noreferrer"&gt;ShadowForge Cyber Exploit Verification Repository&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://raw.githubusercontent.com/ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept/main/README.md" rel="noopener noreferrer"&gt;ShadowForge Cyber Vulnerability Verification Documentation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-76504" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-76504 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-73606: CVE-2026-73606: Authorization Bypass and Information Disclosure in SiYuan /api/block/getRefIDs Endpoint</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Thu, 01 Oct 2026 17:30:29 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-73606-cve-2026-73606-authorization-bypass-and-information-disclosure-in-siyuan-4c31</link>
      <guid>https://dev.to/cverports/cve-2026-73606-cve-2026-73606-authorization-bypass-and-information-disclosure-in-siyuan-4c31</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-73606: Authorization Bypass and Information Disclosure in SiYuan /api/block/getRefIDs Endpoint
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-73606&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 6.9&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An authorization bypass and information disclosure vulnerability in the SiYuan personal knowledge management system before version 3.7.4 allows unauthenticated attackers to query block relationship metadata from password-protected documents.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;Unauthenticated API requests to &lt;code&gt;/api/block/getRefIDs&lt;/code&gt; bypass password checks, leaking relationship hierarchies in SiYuan.&lt;/p&gt;




&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-639&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network (AV:N)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v4.0 Score&lt;/strong&gt;: 6.9 (Medium)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00325 (Percentile: 23.20%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: None (No public exploit)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CISA KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Affected Component&lt;/strong&gt;: kernel/api/block.go (/api/block/getRefIDs)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;SiYuan personal knowledge management system&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SiYuan&lt;/strong&gt;: &amp;lt; 3.7.4 (Fixed in: &lt;code&gt;3.7.4&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade SiYuan kernel to v3.7.4 or later.&lt;/li&gt;
&lt;li&gt;Disable anonymous publish mode if immediate upgrade is not feasible.&lt;/li&gt;
&lt;li&gt;Enforce IP-level access controls to the SiYuan kernel api endpoint.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Verify the currently deployed SiYuan version.&lt;/li&gt;
&lt;li&gt;Update deployment configurations (Docker Compose, systemd, or native binaries) to reference v3.7.4 or later.&lt;/li&gt;
&lt;li&gt;Test endpoint response behavior by issuing unauthenticated POST requests to /api/block/getRefIDs to confirm password-protected paths return filtered results.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vg99-7gj7-2fr5" rel="noopener noreferrer"&gt;Official GitHub Security Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getrefids" rel="noopener noreferrer"&gt;VulnCheck Security Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-73606" rel="noopener noreferrer"&gt;NIST National Vulnerability Database (NVD)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-73606" rel="noopener noreferrer"&gt;CVE.org Record&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan" rel="noopener noreferrer"&gt;SiYuan Repository&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0" rel="noopener noreferrer"&gt;SiYuan v3.8.0 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-73606" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-73606 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>CVE-2026-73605: CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan</title>
      <dc:creator>CVE Reports</dc:creator>
      <pubDate>Thu, 01 Oct 2026 16:30:30 +0000</pubDate>
      <link>https://dev.to/cverports/cve-2026-73605-cve-2026-73605-path-traversal-and-file-existence-oracle-via-getuniquefilename-j76</link>
      <guid>https://dev.to/cverports/cve-2026-73605-cve-2026-73605-path-traversal-and-file-existence-oracle-via-getuniquefilename-j76</guid>
      <description>&lt;h1&gt;
  
  
  CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability ID:&lt;/strong&gt; CVE-2026-73605&lt;br&gt;
&lt;strong&gt;CVSS Score:&lt;/strong&gt; 6.9&lt;br&gt;
&lt;strong&gt;Published:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An authorization bypass and path traversal vulnerability exists in the SiYuan knowledge workspace platform. The vulnerability is located in the '/api/file/getUniqueFilename' endpoint inside the 'github.com/siyuan-note/siyuan/kernel' package. Under default configurations, this route is exposed to users who satisfy basic authentication middleware checks, which includes anonymous readers in publish mode. By supplying unvalidated absolute paths, remote attackers can verify the existence of files and directories across the host operating system, establishing a high-fidelity file existence oracle.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;Unauthenticated remote users can verify the existence of files and folders on the host operating system by sending crafted path parameters to the SiYuan file utility endpoint, leading to sensitive host system information disclosure.&lt;/p&gt;




&lt;h3&gt;
  
  
  ⚠️ Exploit Status: POC
&lt;/h3&gt;

&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CWE ID&lt;/strong&gt;: CWE-862&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attack Vector&lt;/strong&gt;: Network (AV:N)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVSS v4.0 Base Score&lt;/strong&gt;: 6.9&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;EPSS Score&lt;/strong&gt;: 0.00325 (Percentile: 23.19%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impact&lt;/strong&gt;: Filesystem structure reconnaissance&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Status&lt;/strong&gt;: Proof-of-Concept Available&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;KEV Status&lt;/strong&gt;: Not Listed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected Systems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;SiYuan personal knowledge management system&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SiYuan&lt;/strong&gt;: &amp;lt; 3.7.4 (Fixed in: &lt;code&gt;3.7.4&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Exploit Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p" rel="noopener noreferrer"&gt;GitHub Security Advisory&lt;/a&gt;: Exploit methodology and vulnerability overview documented in the official advisory.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Mitigation Strategies
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade SiYuan to version v3.7.4 or later&lt;/li&gt;
&lt;li&gt;Restrict access to the SiYuan API via network access control lists&lt;/li&gt;
&lt;li&gt;Disable anonymous publish mode if not strictly required&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Remediation Steps:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify all active instances of SiYuan running versions prior to v3.7.4&lt;/li&gt;
&lt;li&gt;Apply the v3.7.4 update from the official source&lt;/li&gt;
&lt;li&gt;Verify that the /api/file/getUniqueFilename endpoint no longer accepts absolute paths outside the workspace&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-73605" rel="noopener noreferrer"&gt;NVD - CVE-2026-73605&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-73605" rel="noopener noreferrer"&gt;CVE.org - CVE-2026-73605&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p" rel="noopener noreferrer"&gt;GitHub Security Advisory GHSA-hf8h-97gm-4x2p&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-getuniquefilename" rel="noopener noreferrer"&gt;VulnCheck Advisory Portal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siyuan-note/siyuan" rel="noopener noreferrer"&gt;SiYuan Repository&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://cvereports.com/reports/CVE-2026-73605" rel="noopener noreferrer"&gt;Read the full report for CVE-2026-73605 on our website&lt;/a&gt; for more details including interactive diagrams and full exploit analysis.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
