Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

113 advisories

Loading
vm2 contains a sandbox escape vulnerability Critical
CVE-2026-93605 was published for vm2 (npm) Oct 7, 2026
vm2: Sandbox Escape (NodeVM) Critical
CVE-2026-92955 was published for vm2 (npm) Oct 5, 2026
c0rydoras Credited to c0rydoras
rexpository Credited to rexpository
abisheikM1 Credited to abisheikM1, amagesh1, and Den1al amagesh1 amagesh1
Den1al Den1al
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass Critical
CVE-2026-92956 was published for vm2 (npm) Oct 5, 2026
thesmartshadow Credited to thesmartshadow and zolbooo zolbooo zolbooo
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical
CVE-2026-92935 was published for vm2 (npm) Oct 1, 2026
lexdotdev Credited to lexdotdev
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector Critical
CVE-2026-92944 was published for vm2 (npm) Oct 1, 2026
YMs0ra Credited to YMs0ra
Duplicate Advisory: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix Critical
GHSA-5v7w-95g5-pj6q was published for vm2 (npm) Sep 17, 2026 • withdrawn
Duplicate Advisory: Sandbox Escape (NodeVM) Critical
GHSA-gg6f-mhqm-f7gp was published for vm2 (npm) Sep 17, 2026 • withdrawn
portyu9 Credited to portyu9
Duplicate Advisory: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical
GHSA-9fxx-mv6c-j5xp was published for vm2 (npm) Sep 17, 2026 • withdrawn
Applications that evaluate Spring Expression Language (SpEL) expressions using... Critical Unreviewed
CVE-2026-59283 was published Aug 27, 2026
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter Moderate
GHSA-9w56-46f6-3qhx was published for asteval (pip) Aug 20, 2026
thegr1ffyn Credited to thegr1ffyn
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user,... Critical Unreviewed
CVE-2026-71470 was published Aug 19, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, PowerliftLog, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren PowerliftLog PowerliftLog zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading Moderate
CVE-2026-48775 was published for langgraph-checkpoint (pip) Jun 25, 2026
pucagit Credited to pucagit
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API Critical
CVE-2026-53753 was published for crawl4ai (pip) Jun 16, 2026
q1uf3ng Credited to q1uf3ng, August829, and ntohidi August829 August829
ntohidi ntohidi
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass Critical
CVE-2026-47210 was published for vm2 (npm) May 29, 2026
RealHurrison Credited to RealHurrison
ProTip! Advisories are also available from the GraphQL API