
Ryx@PadhiyarRushi
Four vm2 sandbox escapes landed in one disclosure window. CVE-2026-92941 (CVSS 10) plus three more at 9.9. Any service that still runs untrusted JavaScript inside patriksimek/vm2 is exposed to full sandbox escape. High signal if you run Node tooling that evaluates third-party code. https://cvebrief.com/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #NodeJS
0000022
828 followersView on X
