Authorization Bypass Vulnerability in vm2 by GitHub
CVE-2026-92951

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92951?

The vm2 module, prior to version 3.11.7, has an authorization bypass issue stemming from its flawed external package allowlist validation. Instead of enforcing strict boundary conditions for package names, it employs non-exact substring matching. This can allow attackers to craft a package name that collides with a valid allowlisted substring, leading to unauthorized host package loading and execution within the host context, thus posing a significant risk to overall system integrity.

Affected Version(s)

vm2 0 < 3.11.7

vm2 3.11.7

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

XlabAITeam
keenanwgn
liangjs
.