VulnSea

patriksimek has 34 CVEs on record. Disclosure cadence is accelerating: 34 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 34. The median CVSS is 9.9 (critical), with 20 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-693 (9) and CWE-913 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.9
Publish → KEV
Last 90 days
34 prev 0

Products

  • vm2 34
34
Total CVEs
20
Critical
0
CISA KEV
0
Exploited

patriksimek vulnerabilities

CVEs affecting patriksimek, newest first. Open any entry for full detail, references, and exploit status.

34 CVEsRSS

CVE-2026-92936Medium· 5.8PoC
4d ago

vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting

vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling ev…

Twilightpatriksimek · vm2EPSS 0.41%via NVD
CVE-2026-92935Critical· 9.0
4d ago

vm2 is a sandbox for running untrusted Node.js code

vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require`…

Midnightpatriksimek · vm2EPSS 0.50%via NVD
CVE-2026-92934Critical· 9.0PoC
4d ago

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle d…

Abyssalpatriksimek · vm2EPSS 0.74%via NVD
CVE-2026-92933Medium· 5.8PoC
4d ago

vm2 is a sandbox for running untrusted Node.js code

vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, util)` in `defaultBuiltinLoaderUtil`), and the deprecated …

Twilightpatriksimek · vm2EPSS 0.27%via NVD
patriksimek vulnerabilities (CVEs) — page 2 · VulnSea