Vulnerability Description
vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-7q3f-wx44-378m
- https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-v
FAQ
What is CVE-2026-92945?
CVE-2026-92945 is a vulnerability with a CVSS score of 4.2 (MEDIUM). vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allow...
How severe is CVE-2026-92945?
CVE-2026-92945 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-92945?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.