PT-2026-94316 · Npm · Vm2
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.7
Description
A module allowlist bypass exists in the
isPathAllowedForModule() function. The issue stems from the use of raw string prefix matching instead of boundary-anchored comparison. This allows attackers to access non-allowlisted packages that share a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.Recommendations
Update vm2 to version 3.11.7 or later.
Exploit
Fix
Incorrect Authorization
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2