chiprook
← Security
SecurityOctober 4, 2026, 07:49

vm2 CVE-2026-100721: path allowlist bypassed by prefix match

A vm2 sandbox authorization flaw, CVE-2026-100721, scored 9.5 under CVSS 4.0: the path allowlist matched a raw string prefix with no boundary, so an allowlisted module foo authorized its sibling foo2. The fix shipped in 3.12.2 on Sep 8; only PoC exploitation is known.

vm2 CVE-2026-100721: path allowlist bypassed by prefix match
#Vm2
Read next
Security

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass

Security

MCPVault path filters bypassed: CVE-2026-57441 and CVE-2026-57442

Security

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

Security

CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store