CVE-2026-92945: vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
isPathAllowedForModule decides whether a resolved path belongs to an allowlisted external module using a raw string prefix test. node_modules/foo2 starts with node_modules/foo, so a package whose name merely shares a prefix with an allowlisted one is treated as being inside it, and a relative require from the allowlisted package reaches it even with transitive loading disabled.
References
- github.com/advisories/GHSA-7q3f-wx44-378m
- github.com/patriksimek/vm2/commit/6ac3916da84e060c403e407b6b6318fcc66b0e72
- github.com/patriksimek/vm2/releases/tag/v3.11.7
- github.com/patriksimek/vm2/security/advisories/GHSA-7q3f-wx44-378m
- nvd.nist.gov/vuln/detail/CVE-2026-92945
- www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-via-prefix-matching
Code Behaviors & Features
Detect and mitigate CVE-2026-92945 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →