Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17423
  • npm/illusion-datalab
Malicious code in illusion-datalab (npm) 2 hours ago
  • No fix available
MAL-2026-17362
  • npm/@kelvdra/baileys
Malicious code in @kelvdra/baileys (npm) 8 hours ago
  • No fix available
MAL-2026-17351
  • npm/@bottino/baileys
Malicious code in @bottino/baileys (npm) 8 hours ago
  • No fix available
GHSA-jf8q-945g-9q4c
  • npm/vm2
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks 9 hours ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-qhwx-74w5-xhxq
  • npm/vm2
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape 9 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-jxxv-8r27-vm4p
  • npm/vm2
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts 9 hours ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-h85j-hv3c-qfgq
  • npm/vm2
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent 9 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-c48m-32m9-vx93
  • npm/vm2
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package 9 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-6rh5-qq4q-97xh
  • npm/vm2
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes 9 hours ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-8686-vhfx-7r3j
  • npm/vm2
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process 9 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-633r-hq9m-c4ff
  • npm/vm2
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor 9 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
GHSA-8hr7-r645-pc6w
  • npm/vm2
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE 9 hours ago
  • Fix available
  • Severity - 9.0 (Critical)
GHSA-647f-g98j-qq25
  • npm/vm2
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection 9 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-6w8r-xxw2-g3hx
  • npm/vm2
vm2 allows a sandboxed plugin to execute native code through `node:sqlite` 9 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-46pr-c5wc-xffx
  • npm/vm2
vm2 crypto builtin loads attacker native code through setEngine 9 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-27g9-p43v-cw3v
  • npm/vm2
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector 9 hours ago
  • Fix available
  • Severity - 9.8 (Critical)