{"ok":true,"trend":{"id":627925,"platform":"mastodon","region":"global","key":"🚨 euvd-2026-81591 📊 score: 10.0/10 (cvss v3.1) 📦 product: vm2 🏢 vendor: patriksimek 📅 updated: 2026-10-01 📝 vm2 nodevm c","title":"🚨 EUVD-2026-81591 📊 Score: 10.0/10 (CVSS v3.1) 📦 Product: vm2 🏢 Vendor: patriksimek 📅 Updated: 2026-10-01 📝 vm2 NodeVM c","url":"https://mastodon.social/@EUVD_Bot/117366495111048135","first_seen":"2026-10-01T16:16:12.245658Z","last_seen":"2026-10-01T16:16:12.245658Z","last_rank":10,"peak_rank":10,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.72109375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.","why":"A perfect CVSS score on a widely used JavaScript sandbox library raises immediate concerns about sandbox escapes and trust-store tampering.","tone":"neutral","entities":["vm2","Patrik Simek","ENISA","Node.js"],"summarized_at":"2026-10-01T16:17:47.714267Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1539},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical 10/10 vulnerability flagged in vm2 sandbox library","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-01T16:16:12.245658Z","rank":10,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@EUVD_Bot/117366495111048135","author":"EUVD_Bot","title":null,"snippet":"🚨 EUVD-2026-81591 📊 Score: 10.0/10 (CVSS v3.1) 📦 Product: vm2 🏢 Vendor: patriksimek 📅 Updated: 2026-10-01 📝 vm2 NodeVM can replace the host process TLS trust store 🔗 https:// euvd.enisa.europa.eu/vulnerabi lity/EUVD-2026-81591 # cybersecurity # infosec # euvd # cve #…","posted_at":"2026-10-01T16:03:11.905000Z","likes":0}],"elsewhere":[],"window":"7d"}}