THREAT INTELLIGENCE · RESEARCH · COMMUNITY

Security news,
without the noise.

Practical coverage of vulnerabilities, emerging threats, and the tools shaping modern security.

Reset
Latest intelligence
7 articles
CVE
NVD CVE API · CVE

CVE-2026-92945: vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.