⚠ Withdrawn by GitHub Security Advisories
Withdrawn: October 1, 2026
GHSA-8mvv-mcc3-xwhhLowCVSS 4.2Disclosed before NVD
Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
📋 Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-7q3f-wx44-378m. This link is maintained to preserve external references.
Original Description
vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.
🎯 Affected products1
- npm/vm2:<= 3.11.6