All CVEs — page 197 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows authenticated project members to write arbitrary files outside the project repository, potentially leading to code execution.
This flaw allows attackers to read host process identity and network topology, and hijack the host process DNS resolver, leading to potential data exfiltration and DNS spoofing.
The flaw allows sandboxed code to bypass the built-in deny-list by using `node:`-prefixed specifiers, gaining access to potentially dangerous APIs like `child_process`, which can lead to command execution.
This flaw allows sandbox escape via WebAssembly, enabling access to host Node.js capabilities within a sandboxed environment. It is critical due to the potential for full host system compromise.
This vulnerability allows attackers to escape the sandbox and execute arbitrary code with process context, bypassing security restrictions.
This flaw allows attackers to modify host TypedArray and ArrayBuffer prototypes, leading to potential host-created typed arrays observing attacker-controlled properties. This can compromise data integrity and security.
This flaw allows attackers to bypass the allowlist check in vm2 by using a colliding package name, leading to the execution of unauthorized host packages.
The flaw allows a sandbox escape by bypassing vm2's allowlist, permitting execution of arbitrary JavaScript in a Node.js environment.
This flaw allows sandboxed code to access Node's shared Buffer pool, leading to potential data exposure and denial-of-service conditions.
The vulnerability allows remote code execution when require.external is enabled without an explicit require.root that excludes node_modules, posing a critical risk.
This vulnerability allows attackers to bypass sandbox protections in vm2 versions 3.10.2 through 3.11.6 by exploiting the Promise.prototype.finally() method, leading to arbitrary code execution.