CVE-2026-92945

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
4.2
MEDIUM

Description

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.

Published
September 17, 2026 2:17 PM
Last Modified
September 17, 2026 3:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-22

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.