This advisory has been withdrawn because it is a duplicate of GHSA-7q3f-wx44-378m. This link is maintained to preserve external references.
vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-01T15:26:09Z",
"nvd_published_at": "2026-09-17T14:17:59Z",
"severity": "LOW"
}