PT-2026-105498 · Npm · Vm2

Publicado

2026-09-17

·

Atualizado

2026-09-17

CVSS v3.1

4.2

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7q3f-wx44-378m. This link is maintained to preserve external references.

Original Description

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-8MVV-MCC3-XWHH

Produtos afetados

Vm2