CVE-2026-92945 UNKNOWN

CVE-2026-92945

Published: 2026-09-17

Description

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…