Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2023-37466: vm2 can allow malicious code execution

CVE-2023-37466 · published 3 days ago
Summary

The vm2 library used in Node.js applications can be tricked into running code that an attacker supplies. This affects any project that includes vm2, such as rootio/@rootio/vm2, GitHub Actions/vm2, and vm2_project/vm2. Update to the latest released version of vm2 as soon as possible to apply the fix.

What to do
  • Update vm2 to version 3.9.17-aikido.10.
  • Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
  • Update GitHub Actions vm2 to version 3.10.0.
  • Update rootio @rootio/vm2 to version 3.9.17-root.io.7.
  • Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
  • Update GitHub Actions vm2 to version 3.9.17-aikido.9.
  • Update GitHub Actions vm2 to version 3.9.17-aikido.7.
Affected software
Ecosystem VendorProductAffected versions
Root:npm – vm2 < 3.9.17-aikido.10
Fix: upgrade to 3.9.17-aikido.10
Root:npm rootio @rootio/vm2 < 3.9.17-root.io.10
< 3.9.17-root.io.7
< 3.9.17-root.io.9
Fix: upgrade to 3.9.17-root.io.10
npm GitHub Actions vm2 <= 3.9.19
Fix: upgrade to 3.10.0
– vm2_project vm2 <= 3.9.19
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Root:npm GitHub Actions vm2 < 3.9.17-aikido.9
< 3.9.17-aikido.7
Fix: upgrade to 3.9.17-aikido.9
Original advisory text
CVE-2023-37466 in vm2 - Patched by Root
Root has patched CVE-2023-37466 in the vm2 package for Root:npm. Multiple fixed versions available.
Severity
10.0 Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 4%
Type
CWE-94Code Injection
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta