{"ok":true,"trend":{"id":627924,"platform":"mastodon","region":"global","key":"🚨 euvd-2026-81594 📊 score: 2.3/10 (cvss v3.1) 📦 product: vm2 🏢 vendor: patriksimek 📅 updated: 2026-10-01 📝 vm2: external","title":"🚨 EUVD-2026-81594 📊 Score: 2.3/10 (CVSS v3.1) 📦 Product: vm2 🏢 Vendor: patriksimek 📅 Updated: 2026-10-01 📝 vm2: External","url":"https://mastodon.social/@EUVD_Bot/117366498722466022","first_seen":"2026-10-01T16:16:12.245658Z","last_seen":"2026-10-01T16:16:12.245658Z","last_rank":9,"peak_rank":9,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.75546875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A new vulnerability entry, EUVD-2026-81594, has been published for the vm2 JavaScript sandbox library maintained by patriksimek. The flaw carries a low CVSS v3.1 score of 2.3 out of 10 and stems from the external module allowlist using a raw prefix test, meaning a sibling package sharing a name prefix is incorrectly treated as allowlisted. The entry was updated on 1 October 2026.","why":"New security advisory entries are routinely shared and discussed in cybersecurity communities when published, even for low-severity issues.","tone":"neutral","entities":["vm2","patriksimek","ENISA"],"summarized_at":"2026-10-01T16:17:45.143048Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1539},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Low-severity vm2 sandbox flaw disclosed under EUVD-2026-81594","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-01T16:16:12.245658Z","rank":9,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@EUVD_Bot/117366498722466022","author":"EUVD_Bot","title":null,"snippet":"🚨 EUVD-2026-81594 📊 Score: 2.3/10 (CVSS v3.1) 📦 Product: vm2 🏢 Vendor: patriksimek 📅 Updated: 2026-10-01 📝 vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted 🔗 https:// euvd.enisa.europa.eu/vulnerabi…","posted_at":"2026-10-01T16:04:07.013000Z","likes":0}],"elsewhere":[],"window":"7d"}}