Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-92945

MEDIUM NVD
CVSS Score 4.2
Severity MEDIUM
Published Sep 17, 2026
Vendor unknown

Description

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.

References