{"id":"GHSA-8mvv-mcc3-xwhh","title":"Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted","summary":"Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted","severity":"low","cvss":4.2,"cwe":["CWE-22"],"vendor":"vm2","product":"vm2","ecosystem":"npm","affected":["vm2 <= 3.11.6"],"published":"2026-09-17","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:26:10Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-8mvv-mcc3-xwhh","references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-7q3f-wx44-378m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92945"},{"url":"https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-via-prefix-matching"},{"url":"https://github.com/advisories/GHSA-8mvv-mcc3-xwhh"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-01T15:48:17.828Z","slug":"GHSA-8mvv-mcc3-xwhh","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-7q3f-wx44-378m. This link is maintained to preserve external references.\n\n## Original Description\nvm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.\n\n## Affected packages\n\n- `vm2 <= 3.11.6`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}