Authorization Bypass Vulnerability in vm2 by GitHub
CVE-2026-92951
9.4CRITICAL
What is CVE-2026-92951?
The vm2 module, prior to version 3.11.7, has an authorization bypass issue stemming from its flawed external package allowlist validation. Instead of enforcing strict boundary conditions for package names, it employs non-exact substring matching. This can allow attackers to craft a package name that collides with a valid allowlisted substring, leading to unauthorized host package loading and execution within the host context, thus posing a significant risk to overall system integrity.
Affected Version(s)
vm2 0 < 3.11.7
vm2 3.11.7
