CVE-2026-92945: Patriksimek VM2

Medium severity, CVSS 4.2. EPSS: 0.3% chance of exploitation in the next 30 days.

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.

Affected products

Published 2026-09-17. Last modified 2026-09-17.