⚠ Withdrawn by GitHub Security Advisories

Withdrawn: October 1, 2026

GHSA-8mvv-mcc3-xwhhLowCVSS 4.2Disclosed before NVD

Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted

Published
September 17, 2026
Last Modified
October 1, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7q3f-wx44-378m. This link is maintained to preserve external references.

Original Description

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.

🎯 Affected products1

  • npm/vm2:<= 3.11.6

🔗 References (4)