Upwind Security MDR[verified]@UpwindMDRDisclosure
The text alerts that a malicious npm package vm2 (CVE-2026-24118) can intercept data and alter application behavior, urging immediate removal and treating affected systems as compromised.
Joey Romaine 🇺🇸 |=★=|[verified]@Tank23x0General
The post announces an advisory for CVE‑2026‑24118 involving a VM2 sandbox breakout via __lookupGetter__, but gives no explicit PoC, exploit code, remediation, or evidence of active exploitation.
Lyrie.ai[verified]@lyrie_aiPatch
The brief update reports that CVE‑2026‑24118 and CVE‑2026‑43999 have been patched in version 3.11.0, providing CVSS scores and attack vector details for each vulnerability.
Lyrie.ai[verified]@lyrie_aiDisclosure
The snippet announces six critical vulnerabilities in the Node.js vm2 sandbox library but offers no proof of exploitation, PoC, or patch details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces a critical remote code execution vulnerability (CVE-2026-24118) in the npm library vm2, detailing how attackers can bypass sandbox isolation to execute arbitrary code.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces a critical remote code execution vulnerability (CVE‑2026‑24118) in npm’s vm2 library, detailing its severity (CVSS 9.8) and the ability to bypass sandbox isolation in versions prior to 3.11.0, but it does not provide a PoC link, exploit code, or evidence of active exploitation.
Lyrie.ai[verified]@lyrie_aiDisclosure
Six critical RCE vulnerabilities in the Node.js vm2 library have been announced with a CVSS score of 10.0. No PoC, exploit code, or mitigation details are provided.
Lyrie.ai[verified]@lyrie_aiDisclosure
CVE-2026-24118 allows arbitrary code execution via vm2 for versions < 3.11.0, with a high CVSS score of 9.8, but no PoC, exploit code, or patch details are provided.