Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-m5w8-4gq2-6f8x
  • npm/vm2
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) 17 Aug
  • Fix available
  • Severity - 10.0 (Critical)
CLEANSTART-2026-EQ29985
  • CleanStart/n8n
Security fix for ghsa-m5w8-4gq2-6f8x applied in: n8n 2.28.0-r4 yesterday
  • Fix available
  • Severity - 10.0 (Critical)
ROOT-APP-NPM-GHSA-m5w8-4gq2-6f8x
  • Root:npm/@rootio/vm2
  • Root:npm/vm2
GHSA-m5w8-4gq2-6f8x in vm2 - Patched by Root 3 days ago
  • Fix available
ECHO-a343-4f0a-64e7
  • Echo:npm/vm2
See record for full details 28 Sep
  • Fix available
CLSA-2026-1790461115
  • TuxCare:npm/vm2
TuxCare security update for vm2 (4 CVEs) 26 Sep
  • Fix available
CVE-2026-92960
  • github.com/patriksimek/vm2
vm2 before 3.11.6 Process-wide State Exposure via os and dns 17 Sep
  • Fix available
  • Severity - 10.0 (Critical)
CLSA-2026-1787860907
  • TuxCare:npm/vm2
TuxCare security update for vm2 (34 CVEs) 27 Aug
  • Fix available
MINI-hw8w-gfqc-mvp2
  • MinimOS/n8n
See record for full details 20 Aug
  • Fix available