<Vulnerability name="CVE-2026-92945">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-17T13:46:06</PublicDate>
    <Bugzilla id="2536029" url="https://bugzilla.redhat.com/show_bug.cgi?id=2536029" xml:lang="en:us">
vm2: vm2: Module allowlist bypass allows access to restricted packages
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>4.2</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1025</CWE>
    <Details xml:lang="en:us" source="Mitre">
vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in vm2. This vulnerability allows an attacker to bypass the module allowlist, a security feature designed to restrict access to certain software modules. The flaw occurs due to an incorrect string comparison method used in the `isPathAllowedForModule` function. By exploiting this, an attacker can load and interact with modules that should be inaccessible, potentially leading to information disclosure or the execution of unintended code.
    </Details>
    <Statement xml:lang="en:us">
Moderate impact. This vulnerability in the `vm2` component, present in Red Hat Ansible Automation Platform and Red Hat Developer Hub, allows for a module allowlist bypass. Exploitation requires an attacker to perform relative module imports from an already allowlisted package when transitive loading is disabled, leading to access to restricted packages.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhdh/rhdh-hub-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ansible-automation-platform/automation-portal</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ansible-automation-platform/bootc-automation-portal-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-92945
https://nvd.nist.gov/vuln/detail/CVE-2026-92945
https://github.com/patriksimek/vm2/security/advisories/GHSA-7q3f-wx44-378m
https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-via-prefix-matching
    </References>
</Vulnerability>