Impact
vm2 before 3.11.7 contains a flaw in the module allowlist check: the function that verifies whether a module path is allowed uses raw string prefix matching instead of a boundary‑anchored comparison. This means an attacker can load a module that is not on the allowlist but shares a common prefix with an allowlisted module by performing a relative require from an allowlisted package. The ability to execute such modules in the context of the allowed module can enable the attacker to run arbitrary code and further compromise the application.
Affected Systems
The vulnerability affects all installations of patriksimek vm2 where the module allowlist is used, specifically any release earlier than version 3.11.7.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and no EPSS score is available. The flaw is not listed in the CISA KEV catalog. The attack vector requires the attacker to be able to influence the module resolution process, for example by supplying a relative module name that shares a prefix with an allowlisted module while transitive loading is disabled. This typically needs local or insider access rather than remote code execution. Given the limited reach and the absence of known exploits, the practical risk is moderate, mainly posing a threat to trusted code execution rather than enabling an immediate remote takeover.
OpenCVE Enrichment
Github GHSA