Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2023-37466: vm2 can allow malicious code execution
CVE-2023-37466 · published 3 days ago
Summary
The vm2 library used in Node.js applications can be tricked into running code that an attacker supplies. This affects any project that includes vm2, such as rootio/@rootio/vm2, GitHub Actions/vm2, and vm2_project/vm2. Update to the latest released version of vm2 as soon as possible to apply the fix.
What to do
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update GitHub Actions vm2 to version 3.10.0.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.7.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
- Update GitHub Actions vm2 to version 3.9.17-aikido.9.
- Update GitHub Actions vm2 to version 3.9.17-aikido.7.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 Fix: upgrade to 3.9.17-aikido.10
|
| Root:npm | rootio | @rootio/vm2 |
< 3.9.17-root.io.10 < 3.9.17-root.io.7 < 3.9.17-root.io.9 Fix: upgrade to 3.9.17-root.io.10
|
| npm | GitHub Actions | vm2 |
<= 3.9.19 Fix: upgrade to 3.10.0
|
| – | vm2_project | vm2 |
<= 3.9.19 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
| Root:npm | GitHub Actions | vm2 |
< 3.9.17-aikido.9 < 3.9.17-aikido.7 Fix: upgrade to 3.9.17-aikido.9
|
Original advisory text
CVE-2023-37466 in vm2 - Patched by Root
Root has patched CVE-2023-37466 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5
- https://nvd.nist.gov/vuln/detail/CVE-2023-37466
- https://gist.github.com/leesh3288/f693061e6523c97274ad5298eb2c74e9
- https://security.netapp.com/advisory/ntap-20230831-0007
- https://security.netapp.com/advisory/ntap-20241108-0002
- https://github.com/patriksimek/vm2/commit/d9a1fde8ec5a5a9c9e5a69bf91d703950859d7...
- https://github.com/patriksimek/vm2/releases/tag/v3.10.0
- https://github.com/advisories/GHSA-cchq-frgv-rjh5
- https://security.netapp.com/advisory/ntap-20241108-0002/
Severity
10.0
Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 4%
Type
CWE-94Code Injection
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta