CyberRota Analysis
AI-GeneratedThe vulnerability in vm2 prior to version 3.11.7 allows attackers to bypass the external package allowlist due to improper substring matching, enabling the execution of unauthorized host packages. This critical flaw poses significant risks to applications relying on vm2 for sandboxing, as it can lead to arbitrary code execution in the host context. Organizations using vm2 for security-sensitive operations should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.