Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #9
Low-severity vm2 sandbox flaw disclosed under EUVD-2026-81594
Original: π¨ EUVD-2026-81594 π Score: 2.3/10 (CVSS v3.1) π¦ Product: vm2 π’ Vendor: patriksimek π Updated: 2026-10-01 π vm2: External
A new vulnerability entry, EUVD-2026-81594, has been published for the vm2 JavaScript sandbox library maintained by patriksimek. The flaw carries a low CVSS v3.1 score of 2.3 out of 10 and stems from the external module allowlist using a raw prefix test, meaning a sibling package sharing a name prefix is incorrectly treated as allowlisted. The entry was updated on 1 October 2026.
Why now: New security advisory entries are routinely shared and discussed in cybersecurity communities when published, even for low-severity issues.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/627924