{"id":"GHSA-6fvh-fgmg-3x7v","title":"Duplicate Advisory: vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package","summary":"Duplicate Advisory: vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package","severity":"critical","cvss":9.9,"cwe":["CWE-706"],"vendor":"vm2","product":"vm2","ecosystem":"npm","affected":["vm2 <= 3.11.6"],"published":"2026-09-17","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:37:01Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-6fvh-fgmg-3x7v","references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-c48m-32m9-vx93"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92951"},{"url":"https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-via-custom-resolver"},{"url":"https://github.com/advisories/GHSA-6fvh-fgmg-3x7v"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-01T15:48:17.823Z","slug":"GHSA-6fvh-fgmg-3x7v","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-c48m-32m9-vx93. This link is maintained to preserve external references.\n\n## Original Description\nvm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.\n\n## Affected packages\n\n- `vm2 <= 3.11.6`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":54.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}