Threats Tagged 'ghsa-m5w8-4gq2-6f8x'
View all threats tagged with 'ghsa-m5w8-4gq2-6f8x'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-m5w8-4gq2-6f8x'
Click on any threat for detailed analysis and mitigation recommendations
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) 0 The vm2 NodeVM module with configuration builtin: ['*'] exposes the 'os' and 'dns' built-in modules, allowing sandboxed code to read sensitive host process information and perform process-wide state modifications. This includes reading host user info, network interfaces, and hostname, as well as hijacking DNS resolution via dns.setServers(). The vulnerability affects vm2 versions prior to 3.11.6 and has a critical CVSS score of 10. A patch is available to mitigate this issue by adding 'os' and 'dns' to the dangerous builtins list, preventing their exposure under the wildcard configuration. Join the discussion | GCVE Database | 08/17/2026, 17:32:47 UTC Added: 08/17/2026, 22:36:09 UTC |
Showing 1 to 1 of 1 result