{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43998.json"
      }
    ],
    "title": "vm2: vm2: Remote code execution due to path restriction bypass via symlinks",
    "tracking": {
      "current_release_date": "2026-08-05T18:21:50+00:00",
      "generator": {
        "date": "2026-08-05T18:21:50+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.12"
        }
      },
      "id": "CVE-2026-43998",
      "initial_release_date": "2026-05-13T17:19:44.406000+00:00",
      "revision_history": [
        {
          "date": "2026-05-13T17:19:44.406000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-21T07:13:24+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-05T18:21:50+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Developer Hub",
                "product": {
                  "name": "Red Hat Developer Hub",
                  "product_id": "red_hat_developer_hub",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:rhdh:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Developer Hub"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Ansible Automation Platform 2.1",
                "product": {
                  "name": "Red Hat Ansible Automation Platform 2.1",
                  "product_id": "Red Hat Ansible Automation Platform 2.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ansible_portal:2.1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Ansible Automation Platform"
          },
          {
            "category": "product_version",
            "name": "rhdh/rhdh-hub-rhel9",
            "product": {
              "name": "rhdh/rhdh-hub-rhel9",
              "product_id": "rhdh/rhdh-hub-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/rhdh-hub-rhel9?repository_url=registry.redhat.io/rhdh/rhdh-hub-rhel9"
              }
            }
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
                "product": {
                  "name": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
                  "product_id": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/automation-portal@sha256%3Aa85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d?arch=amd64&repository_url=registry.redhat.io/ansible-automation-platform/automation-portal&tag=1785854226"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64 as a component of Red Hat Ansible Automation Platform 2.1",
          "product_id": "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64"
        },
        "product_reference": "registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
        "relates_to_product_reference": "Red Hat Ansible Automation Platform 2.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub",
          "product_id": "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
        },
        "product_reference": "rhdh/rhdh-hub-rhel9",
        "relates_to_product_reference": "red_hat_developer_hub"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-43998",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "discovery_date": "2026-05-13T18:02:11.809808+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2477206"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in vm2 3.10.5. NodeVM require.root path checks use path.resolve() without dereferencing symlinks, while Node require() follows symlinks, allowing sandboxed code to load host modules outside the allowed root and achieve remote code execution. Fixed in 3.11.0.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "vm2: vm2: Remote code execution due to path restriction bypass via symlinks",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "vm2 NodeVM is vulnerable to require.root bypass via filesystem symlinks, enabling sandboxed code to load arbitrary host-realm modules. An attacker with low privileges who can run code in a NodeVM with require restrictions and symlink-accessible paths may achieve remote code execution. Fixed in vm2 3.11.0.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64"
        ],
        "known_not_affected": [
          "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-43998"
        },
        {
          "category": "external",
          "summary": "RHBZ#2477206",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477206"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-43998",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43998"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-43998",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43998"
        },
        {
          "category": "external",
          "summary": "https://github.com/patriksimek/vm2/security/advisories/GHSA-cp6g-6699-wx9c",
          "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-cp6g-6699-wx9c"
        }
      ],
      "release_date": "2026-05-13T17:19:44.406000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-05T16:35:19+00:00",
          "details": "For more about Ansible plugins for Red Hat Developer Hub, see References links",
          "product_ids": [
            "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:50850"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "Red Hat Ansible Automation Platform 2.1:registry.redhat.io/ansible-automation-platform/automation-portal@sha256:a85a548cb563a32be76c6e7e015fd57d340e068e321bf34b060d9eb901c33c4d_amd64",
            "red_hat_developer_hub:rhdh/rhdh-hub-rhel9"
          ]
        }
      ],
      "title": "vm2: vm2: Remote code execution due to path restriction bypass via symlinks"
    }
  ]
}