CVE-2026-92951
published 2026-09-17CVE-2026-92951: vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of…
PriorityP261critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.54%
43.3th percentile
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform | automation-portal | — | — |
| ansible-automation-platform | bootc-automation-portal-rhel9 | — | — |
| patriksimek | vm2 | < 3.11.7 | 3.11.7 |
| rhdh | red-hat-developer-hub-backstage-plugin-lightspeed-backend | — | — |
| rhdh | red-hat-developer-hub-backstage-plugin-orchestrator-backend | — | — |
| rhdh | rhdh-hub-rhel9 | — | — |
| vm2_project | vm2 | >= 0 < 3.11.7 | 3.11.7 |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
ghsa·2026-10-01
CVE-2026-92951 [CRITICAL] CWE-706 vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
### Summary
vm2 is a sandbox library for isolating and executing untrusted JavaScript code inside a Node.js process. It can restrict access to built-in modules and external packages.
When `NodeVM` enables an `external` allowlist together with a custom `resolve` callback, vm2 checks the requested package name with a non-exact match. For example, if the allowlist only permits `left-pad`, an attacker can still bypass the check with a colliding package name such as `evil-left-pad`, because it contains the allowlisted name.
If the colliding package already exists in a host path resolvable by the custom resolver, or if the target application's custom resolver / dependency-management workf
GHSA
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation.
ghsa_unreviewed·2026-09-17
CVE-2026-92951 [CRITICAL] CWE-706 vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation.
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.
Red Hat
vm2: vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
vendor_redhat·2026-09-17·CVSS 9.9
CVE-2026-92951 [CRITICAL] CWE-706 vm2: vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
vm2: vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.
A flaw was found in vm2. The external package allowlist improperly validates package names using substring matching rather than exact name boundaries. An attacker capable of running code within the sandbox can exploit this issue by requesting a package name containing an allowlisted substring, allowing them to load unauthorized hos
No detection rules found.
No public exploits indexed.
2026-09-17
Published