{"id":"CVE-2026-92951","published":"2026-09-17T14:18:00.827","lastModified":"2026-09-17T20:18:59.610","description":"vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-706"],"vendors":[],"products":[],"references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-c48m-32m9-vx93","tags":[]},{"url":"https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-via-custom-resolver","tags":[]}],"exploitRefs":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-c48m-32m9-vx93","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows attackers to bypass the allowlist check in vm2 by using a colliding package name, leading to the execution of unauthorized host packages.","exploitability":"Exploitation is relatively straightforward given the preconditions of a colliding package name, making it a high-risk vulnerability.","blast_radius":"If exploited, this vulnerability could lead to the execution of arbitrary code in the host context, potentially resulting in full system compromise.","remediation":"Upgrade to vm2 version 3.11.7 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","rce","package-execution","vm2"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:58:16.695Z"}}