Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-11 02:37:10 EDT

Explore

PostsPeople
LatestRanked
@stackflag.bsky.socialSep 17, 2026, 4:00 PM

CVE-2026-92938 - vm2
Versions 3.11.3 through 3.11.6 of the vm2 sandbox let code inside a plugin access the underlying Node.js SQLite library and load native code. This can let an attacker run arbitrary…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:00 PM

CVE-2026-92937 - vm2
The vm2 sandbox library version 3.11.6 can be tricked into exposing the underlying Node.js process, allowing untrusted code to execute commands on the server. This occurs when a rejected…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 3:50 PM

CVE-2026-92935 - vm2
Versions of the vm2 sandbox between 3.11.4 and 3.11.6 let a specially crafted script bypass the isolation and load the host vm2 module. This lets an attacker create a new sandbox with…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 3:40 PM

CVE-2026-92960 - vm2
The vm2 sandbox library, versions earlier than 3.11.6, does not properly block certain system functions. As a result, code running inside the sandbox can see details about the server it…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 3:40 PM

CVE-2026-92955 - vm2
The vm2 package used to isolate JavaScript code can be bypassed in versions older than 3.11.8, allowing a malicious script to break out of its sandbox and run commands on the server…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 3:30 PM

CVE-2026-92950 - vm2
The vm2 sandbox tool version before 3.11.7 lets a malicious script run on the main server when used from the command line. This bypasses the intended isolation and could let an attacker…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 3:30 PM

CVE-2026-92939 - vm2
The vm2 library version 3.11.3 through 3.11.6 lets code running inside its sandbox call a cryptography function that can load a native library from a file path. An attacker who can…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 3:20 PM

CVE-2026-92934 - vm2
The vm2 JavaScript sandbox library, versions earlier than 3.11.8, can be tricked into letting malicious code break out of its isolated environment. This could let an attacker run…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 9, 2026, 9:50 AM

CVE-2023-37466 - vm2
vm2, a Node.js library, has critical security issues that could let hackers run unauthorized code. This could happen if you're using an outdated version of vm2. Update to version…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #rootio #Rootnpm #CVE #infosec

@stackflag.bsky.socialSep 9, 2026, 9:50 AM

CVE-2026-22709 - vm2
An attacker can escape the sandbox and run arbitrary code on a server running an out-of-date version of vm2 for Node.js. This could allow unauthorized access or data theft. Update to…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #rootio #Rootnpm #CVE #infosec

@stackflag.bsky.socialSep 9, 2026, 9:40 AM

CVE-2026-26956 - vm2
A vulnerability in vm2 version 3.10.4 allows an attacker to escape the sandbox and run any code on the host machine. This means an attacker could potentially take control of your…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #GitHubActions #npm #CVE #infosec

@stackflag.bsky.socialSep 9, 2026, 9:20 AM

CVE-2023-37903 - vm2
A vulnerability in the Node.js vm2 sandbox allows attackers to break out of the sandbox and run malicious code. This could give an attacker complete control over your system. There…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #rootio #Rootnpm #CVE #infosec

@stackflag.bsky.socialSep 9, 2026, 9:20 AM

CVE-2023-32314 - vm2
A security issue exists in older versions of the vm2 sandbox for Node.js. If not updated, an attacker could potentially take control of the host system running the sandbox. Users…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #GitHubActions #npm #CVE #infosec

@stackflag.bsky.socialSep 9, 2026, 9:10 AM

CVE-2023-30547 - vm2
vm2, a Node.js sandbox, has a security flaw that could allow attackers to break out of its protective boundaries and run malicious code on your system. This affects versions of…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #GitHubActions #npm #CVE #infosec

@stackflag.bsky.socialSep 9, 2026, 9:10 AM

CVE-2026-24120 - vm2
An outdated version of the vm2 sandbox for Node.js can be tricked into allowing malicious code to break free and run commands on the host computer. This is fixed in version…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #GitHubActions #npm #CVE #infosec