Mmastodon TechnologyCybersecurity first seen 5 h ago, last 5 h ago, peak #10
Critical 10/10 vulnerability flagged in vm2 sandbox library
Original: ๐จ EUVD-2026-81591 ๐ Score: 10.0/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 NodeVM c
A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.
Why now: A perfect CVSS score on a widely used JavaScript sandbox library raises immediate concerns about sandbox escapes and trust-store tampering.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/627925