{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26956.json"
      }
    ],
    "title": "vm2: Node.js: vm2: Arbitrary code execution via sandbox escape",
    "tracking": {
      "current_release_date": "2026-06-30T04:02:15+00:00",
      "generator": {
        "date": "2026-06-30T04:02:15+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-26956",
      "initial_release_date": "2026-05-04T16:37:31.538000+00:00",
      "revision_history": [
        {
          "date": "2026-05-04T16:37:31.538000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-05-15T20:06:44+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T04:02:15+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Developer Hub",
                "product": {
                  "name": "Red Hat Developer Hub",
                  "product_id": "red_hat_developer_hub",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:rhdh:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Developer Hub"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Self-service automation portal 2",
                "product": {
                  "name": "Self-service automation portal 2",
                  "product_id": "self-service_automation_portal_2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ansible_portal:2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Self-service automation portal 2"
          },
          {
            "category": "product_version",
            "name": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
            "product": {
              "name": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
              "product_id": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
              "product_identification_helper": {
                "purl": "pkg:oci/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor?repository_url=registry.redhat.io/rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhdh/rhdh-hub-rhel9",
            "product": {
              "name": "rhdh/rhdh-hub-rhel9",
              "product_id": "rhdh/rhdh-hub-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/rhdh-hub-rhel9?repository_url=registry.redhat.io/rhdh/rhdh-hub-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform/automation-portal",
            "product": {
              "name": "ansible-automation-platform/automation-portal",
              "product_id": "ansible-automation-platform/automation-portal",
              "product_identification_helper": {
                "purl": "pkg:oci/automation-portal?repository_url=registry.redhat.io/ansible-automation-platform/automation-portal"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor as a component of Red Hat Developer Hub",
          "product_id": "red_hat_developer_hub:rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor"
        },
        "product_reference": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
        "relates_to_product_reference": "red_hat_developer_hub"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub",
          "product_id": "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
        },
        "product_reference": "rhdh/rhdh-hub-rhel9",
        "relates_to_product_reference": "red_hat_developer_hub"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform/automation-portal as a component of Self-service automation portal 2",
          "product_id": "self-service_automation_portal_2:ansible-automation-platform/automation-portal"
        },
        "product_reference": "ansible-automation-platform/automation-portal",
        "relates_to_product_reference": "self-service_automation_portal_2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-26956",
      "cwe": {
        "id": "CWE-653",
        "name": "Improper Isolation or Compartmentalization"
      },
      "discovery_date": "2026-05-04T19:04:30.765254+00:00",
      "flags": [
        {
          "label": "component_not_present",
          "product_ids": [
            "red_hat_developer_hub:rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor"
          ]
        },
        {
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
          ]
        },
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "self-service_automation_portal_2:ansible-automation-platform/automation-portal"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2466548"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in vm2, an open-source sandbox for Node.js. An attacker can exploit this vulnerability by running malicious code within the VM.run() function, allowing them to escape the sandbox and gain access to the host process. This can lead to arbitrary code execution on the host system, enabling the attacker to run host commands without any host cooperation.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "vm2: Node.js: vm2: Arbitrary code execution via sandbox escape",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an Important flaw in vm2, an open-source Node.js sandbox, that allows for arbitrary code execution due to a sandbox escape. An attacker can run malicious code within the VM.run() function to gain access to the host process and execute commands without host cooperation.\n\nRed Hat Developer Hub product is not affected by this vulnerability, as the affected `vm2` package is used only as a development dependency and should not be reachable by the user in the final product image. For Red Hat Ansible Portal, this component is already shipping the version 3.10.5 of `vm2` which contains the fix for this vulnerability, thus it's not affected.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_developer_hub:rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
          "red_hat_developer_hub:rhdh/rhdh-hub-rhel9",
          "self-service_automation_portal_2:ansible-automation-platform/automation-portal"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-26956"
        },
        {
          "category": "external",
          "summary": "RHBZ#2466548",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466548"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-26956",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-26956"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-26956",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26956"
        },
        {
          "category": "external",
          "summary": "https://github.com/patriksimek/vm2/releases/tag/v3.10.5",
          "url": "https://github.com/patriksimek/vm2/releases/tag/v3.10.5"
        },
        {
          "category": "external",
          "summary": "https://github.com/patriksimek/vm2/security/advisories/GHSA-ffh4-j6h5-pg66",
          "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-ffh4-j6h5-pg66"
        }
      ],
      "release_date": "2026-05-04T16:37:31.538000+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_developer_hub:rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9",
            "self-service_automation_portal_2:ansible-automation-platform/automation-portal"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_developer_hub:rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9",
            "self-service_automation_portal_2:ansible-automation-platform/automation-portal"
          ]
        }
      ],
      "title": "vm2: Node.js: vm2: Arbitrary code execution via sandbox escape"
    }
  ]
}