{"ok":true,"trend":{"id":627927,"platform":"mastodon","region":"global","key":"🚨 euvd-2026-81589 📊 score: 9.4/10 (cvss v3.1) 📦 product: vm2 🏢 vendor: patriksimek 📅 updated: 2026-10-01 📝 vm2 crypto bu","title":"🚨 EUVD-2026-81589 📊 Score: 9.4/10 (CVSS v3.1) 📦 Product: vm2 🏢 Vendor: patriksimek 📅 Updated: 2026-10-01 📝 vm2 crypto bu","url":"https://mastodon.social/@EUVD_Bot/117366495003917205","first_seen":"2026-10-01T16:16:12.245658Z","last_seen":"2026-10-01T16:16:12.245658Z","last_rank":12,"peak_rank":12,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.66078125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A high-severity vulnerability, EUVD-2026-81589, has been catalogued in vm2, the JavaScript sandbox library maintained by Patrik Simek. Scored 9.4 out of 10 under CVSS v3.1, the flaw involves vm2's crypto builtin loading attacker-supplied native code through the setEngine function, a path that could allow sandbox escapes or arbitrary code execution. The advisory was updated on October 1, 2026, and security teams are being urged to review any systems relying on vm2 for isolating untrusted JavaScript.","why":"Security professionals are tracking a newly updated critical vulnerability in a widely used JavaScript sandboxing library.","tone":"neutral","entities":["vm2","Patrik Simek","ENISA","EUVD-2026-81589"],"summarized_at":"2026-10-01T16:17:52.647114Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1539},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical 9.4-severity vulnerability disclosed in vm2 sandbox library","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-01T16:16:12.245658Z","rank":12,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@EUVD_Bot/117366495003917205","author":"EUVD_Bot","title":null,"snippet":"🚨 EUVD-2026-81589 📊 Score: 9.4/10 (CVSS v3.1) 📦 Product: vm2 🏢 Vendor: patriksimek 📅 Updated: 2026-10-01 📝 vm2 crypto builtin loads attacker native code through setEngine 🔗 https:// euvd.enisa.europa.eu/vulnerabi lity/EUVD-2026-81589 # cybersecurity # infosec # euvd # cve #…","posted_at":"2026-10-01T16:03:10.272000Z","likes":0}],"elsewhere":[],"window":"7d"}}