PT-2026-94316 · Npm · Vm2

·

CVE-2026-92945

·

Published

2026-08-25

·

Updated

2026-09-17

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.7
Description A module allowlist bypass exists in the isPathAllowedForModule() function. The issue stems from the use of raw string prefix matching instead of boundary-anchored comparison. This allows attackers to access non-allowlisted packages that share a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.
Recommendations Update vm2 to version 3.11.7 or later.

Exploit

Fix

Incorrect Authorization

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15016
CVE-2026-92945
GHSA-7Q3F-WX44-378M

Affected Products

Vm2