<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nodejs on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/nodejs/</link><description>Recent content in Nodejs on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 03 Sep 2026 14:50:54 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/nodejs/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical RCE (CVSS 10.0) in vm2 Node.js sandbox, patched in 3.11.7</title><link>https://curadevops.metacog.co.kr/insights/2026-09-03-critical-remote-code-execution-in-vm2-a-widely-used-node-js/</link><pubDate>Thu, 03 Sep 2026 14:50:54 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-09-03-critical-remote-code-execution-in-vm2-a-widely-used-node-js/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> Audit build scripts, custom GitHub Actions, and any Node.js-based pipeline tooling for vm2 usage; if found, update to 3.11.7 and disable require.external — the blog post describes a working exploit path (CVSS 10.0), so exposure is concrete even without a KEV entry. No forced deadline, but the publicly documented exploit makes this a near-term project, not a watch item.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>