Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@stackflag.bsky.socialSep 30, 2026, 8:40 AM

CVE-2022-25893 - vm2
Versions of the vm2 package earlier than 3.9.10 can be tricked into executing any code the attacker wants, breaking the isolation it provides. This could let a malicious user gain access…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #rootio #npm #CVE #infosec

@stackflag.bsky.socialSep 30, 2026, 8:30 AM

CVE-2023-29017 - vm2
Versions of vm2 before 3.9.15 do not correctly handle certain error objects, allowing a malicious script to break out of the sandbox. This could let an attacker execute commands on the…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #rootio #npm #CVE #infosec

@stackflag.bsky.socialSep 30, 2026, 7:50 AM

CVE-2026-43999 - vm2
The vm2 library used in several GitHub repositories could let a malicious user run code they shouldn't be able to. This creates a risk that an attacker could take control of your system…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #rootio #npm #CVE #infosec

@stackflag.bsky.socialSep 28, 2026, 5:40 PM

CVE-2023-29199 - vm2
The vm2 library used in several GitHub Actions and rootio projects may let attackers run code they should not be able to. Updated versions have been released that fix this risk.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #GitHubActions #npm #CVE #infosec

@stackflag.bsky.socialSep 28, 2026, 10:30 AM

CVE-2022-36067 - vm2
The vm2 software used in several projects can be tricked into running code it shouldn’t. This could let an attacker take control of your system or data. Update to the latest…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #GitHubActions #npm #CVE #infosec

@stackflag.bsky.socialSep 27, 2026, 2:20 AM

CVE-2026-100721 - vm2
The vm2 library version earlier than 3.12.2 can be tricked into loading code it should block, allowing code running inside a sandbox to execute on the host system. This happens when a…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 18, 2026, 8:50 PM

CVE-2026-93606 - vm2
Versions of the vm2 package prior to 3.12.1 allow code running inside its sandbox to break out and interact directly with the host system. If the sandbox is given a host function that…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 18, 2026, 8:30 PM

CVE-2026-93605 - vm2
Versions of the vm2 NodeVM library before 3.12.1 let a malicious piece of code access the system's command tool and run any command it wants. This can happen when the sandbox is set to…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 18, 2026, 8:30 PM

CVE-2026-93603 - vm2
The vm2 JavaScript sandbox (versions before 3.12.1) can mistakenly give untrusted code access to the host system's global objects. If your application exposes any non‑strict host…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 5:00 PM

CVE-2026-92957 - vm2
The vm2 sandbox library (versions before 3.11.7) does not correctly block the built‑in child_process module when a deny list uses the “node:” prefix. As a result, code running inside the…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:50 PM

CVE-2026-92956 - vm2
Versions 3.10.1 through 3.11.6 of the vm2 library let code run inside its default sandbox reach the underlying Node.js environment. An attacker could obtain the real process object and…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:50 PM

CVE-2026-92954 - vm2
Versions of the vm2 sandbox library between 3.10.0 and 3.11.5 can let malicious code ignore a failed promise from the host application, causing Node.js to shut down the entire process.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:40 PM

CVE-2026-92953 - vm2
Versions of the vm2 sandbox from 3.11.0 up to 3.11.7 do not stop code running inside the sandbox from changing core JavaScript objects that control binary data handling. This means an…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:40 PM

CVE-2026-92951 - vm2
The vm2 sandbox library can be tricked into loading code that isn’t approved, letting attackers run unwanted programs on the host system. This happens because the library checks package…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:30 PM

CVE-2026-92948 - vm2
Versions of the vm2 library from 3.9.6 up to 3.11.6 let specially crafted code break out of its sandbox when Node.js 24 or later is used and the node:test module is allowed. This means…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:30 PM

CVE-2026-92946 - vm2
The vm2 sandbox library for Node.js can let attackers run commands on the server if the "require.external" option is turned on without proper restrictions. This could let malicious code…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:20 PM

CVE-2026-92944 - vm2
The vm2 library that isolates JavaScript code can be bypassed in versions 3.10.2 through 3.11.6, allowing a crafted script to break out of the sandbox and execute code on the host…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:20 PM

CVE-2026-92947 - vm2
The vm2 module versions before 3.11.7 let code running inside its sandbox access Node’s shared memory buffers. This means a malicious script could read or change data that should stay…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:10 PM

CVE-2026-92941 - vm2
Versions of vm2 between 3.11.3 and 3.11.6 allow code running inside the sandbox to modify the Node.js TLS settings for the whole host. This lets an attacker replace the list of trusted…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

@stackflag.bsky.socialSep 17, 2026, 4:10 PM

CVE-2026-92940 - vm2
Versions 3.11.3 through 3.11.6 of the vm2 tool let code running in an isolated environment see the real HTTPS connections the host makes. This can allow that code to capture…

Too many irrelevant or confusing CVEs? Use stackflag.com

#vm2 #patriksimek #CVE #infosec

Load more