Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 CVE-2026-47208

vm2: Sandbox Breakout Using Promise Species_CVE-2026-47208

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to ...

patriksimek vm2 < 3.11.4 CVE
CRITICAL 10 CVE-2026-47140

vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution_CVE-2026-47140

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_thre...

patriksimek vm2 < 3.11.4 CVE
CRITICAL 10 CVE-2026-47137

vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE_CVE-2026-47137

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodev...

patriksimek vm2 < 3.11.4 CVE
CRITICAL 10 CVE-2026-47131

vm2: Sandbox Escape_CVE-2026-47131

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buf...

patriksimek vm2 < 3.11.4 CVE
CRITICAL 9.3 CVE-2026-10557

Yarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-coded Credentials_CVE-2026-10557

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentia...

Yarbo Yarbo Android/IOS mobile application CVE
CRITICAL 9.1 CVE-2026-50091

Aqara Home Android SDK hardcoded keys_CVE-2026-50091

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic key...

Aqara com.lumiunited.aqarahome 6.0.0 CVE
CRITICAL 9.3 CVE-2026-50090

Aqara OAuth redirect_uri validation bypass_CVE-2026-50090

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain m...

Aqara Cloud OAuth Authorization Endpoint 2026-04-20 CVE
CRITICAL 10 CVE-2026-50086

Aqara unauthenticated AES oracle_CVE-2026-50086

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. T...

Aqara Aqara IAM/SSO Gateway 2026-04-20 CVE
CRITICAL 9.6 CVE-2026-50084

Aqara API cross-account access_CVE-2026-50084

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an in...

Aqara Cloud Production API 2026-04-20 CVE
CRITICAL 9.1 CVE-2026-50083

Aqara hardcoded OAuth client credentials_CVE-2026-50083

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Cred...

Aqara Aquara IAM/SSO Gateway 2026-04-20 CVE