{"id":"CVE-2026-92945","published":"2026-09-17T14:17:59.807","lastModified":"2026-09-17T15:17:00.783","description":"vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.","cvssScore":4.2,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-7q3f-wx44-378m","tags":[]},{"url":"https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-via-prefix-matching","tags":[]}],"exploitRefs":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-7q3f-wx44-378m","tags":[]}],"hasPoc":true,"ai":null}