Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

patriksimek — Vulnerabilities & Security Advisories 77

Browse all 77 CVE security advisories affecting patriksimek. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Patriksimek develops security tools and research, primarily focusing on vulnerability discovery and exploitation frameworks. Historically, their work has frequently involved remote code execution, cross-site scripting, and privilege escalation vulnerabilities across multiple platforms. Notable characteristics include contributions to penetration testing tools and disclosure of critical flaws in widely-used software. While no major security incidents directly attributed to patriksimek have been widely documented, their CVE record demonstrates consistent findings in high-impact vulnerabilities, particularly affecting web applications and system components. Their research often emphasizes practical exploitation techniques, making their findings relevant for both defensive security measures and penetration testing methodologies.

Top products by patriksimek: vm2
CVE ID Title CVSS Severity Published
CVE-2026-92940 vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent — vm2 CWE-668 10.0 Critical 2026-09-17
CVE-2026-92938 vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite — vm2 CWE-693 9.9 Critical 2026-09-17
CVE-2026-92937 vm2 3.11.6 Remote Code Execution via Promise call/apply — vm2 CWE-94 10.0 Critical 2026-09-17
CVE-2026-92936 vm2 3.11.0 before 3.11.7 Information Disclosure via Error Stack — vm2 CWE-209 5.8 Medium 2026-09-17
CVE-2026-92935 vm2 NodeVM Remote Code Execution via Array-Shaped Require — vm2 CWE-913 9.0 Critical 2026-09-17
CVE-2026-92934 vm2 before 3.11.8 Sandbox Escape RCE via AggregateError — vm2 CWE-693 9.0 Critical 2026-09-17
CVE-2026-92933 vm2 before 3.11.8 Information Disclosure via util.getCallSites — vm2 CWE-200 5.8 Medium 2026-09-17
CVE-2026-47683 vm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike — vm2 CWE-770 8.7 High 2026-08-17
CVE-2026-47686 vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE — vm2 CWE-693 9.9 Critical 2026-08-17
CVE-2026-47698 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators — vm2 CWE-913 9.8 Critical 2026-08-17
CVE-2026-47141 vm2: NodeVM observability builtins leak host process and HTTP request data — vm2 CWE-668 - - 2026-06-12
CVE-2026-47210 vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass — vm2 CWE-913 9.8 Critical 2026-06-12
CVE-2026-47208 vm2: Sandbox Breakout Using Promise Species — vm2 CWE-913 10.0 Critical 2026-06-12
CVE-2026-47140 vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution — vm2 CWE-693 10.0 Critical 2026-06-12
CVE-2026-47139 vm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_server — vm2 CWE-693 8.6 High 2026-06-12
CVE-2026-47137 vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE — vm2 CWE-913 10.0 Critical 2026-06-12
CVE-2026-47135 vm2: Sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks — vm2 CWE-693 8.7 High 2026-06-12
CVE-2026-47131 vm2: Sandbox Escape — vm2 CWE-913 10.0 Critical 2026-06-12
CVE-2026-47209 vm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain — vm2 CWE-693 8.6 High 2026-06-12
CVE-2026-44005 vm2: Sandbox escape — vm2 CWE-1321 10.0 Critical 2026-05-13
CVE-2026-45411 vm2: Sandbox Breakout Using Async Generator — vm2 CWE-668 9.8 Critical 2026-05-13
CVE-2026-44009 vm2: Sandbox Breakout Through Null Proto Exception — vm2 CWE-668 9.8 Critical 2026-05-13
CVE-2026-44008 vm2: Snabox breakout via `neutralizeArraySpeciesBatch` — vm2 CWE-668 9.8 Critical 2026-05-13
CVE-2026-44007 vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution — vm2 CWE-284 9.1 Critical 2026-05-13
CVE-2026-44006 vm2: Sandbox Escape — vm2 CWE-94 10.0 Critical 2026-05-13
CVE-2026-44004 vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass) — vm2 CWE-770 7.5 High 2026-05-13
CVE-2026-44003 vm2: Transformer Fast-Path Bypass Exposes Internal State Variable — vm2 CWE-693 5.3 Medium 2026-05-13
CVE-2026-44002 vm2: Host File Path Disclosure via Stack Trace Information Leak — vm2 CWE-209 5.8 Medium 2026-05-13
CVE-2026-44001 vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) — vm2 CWE-248 8.6 High 2026-05-13
CVE-2026-44000 vm2: sandbox boundary bypass via host Promise resolution preserving host object identity — vm2 CWE-693 6.5 Medium 2026-05-13

This page lists every published CVE security advisory associated with patriksimek. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.