Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2023-37903: vm2 package could run malicious code
CVE-2023-37903 · published 3 days ago
Summary
The vm2 JavaScript sandbox library and its related packages can be tricked into executing attacker code. This could let a bad actor run commands on your server if you use vm2 in your applications. Update to the latest released versions of vm2 and any forked packages to fix the problem.
What to do
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
- Update GitHub Actions vm2 to version 3.9.17-aikido.9.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 Fix: upgrade to 3.9.17-aikido.10
|
| Root:npm | rootio | @rootio/vm2 |
< 3.9.17-root.io.10 < 3.9.17-root.io.9 Fix: upgrade to 3.9.17-root.io.10
|
| npm | GitHub Actions | vm2 | <= 3.9.19 |
| – | vm2_project | vm2 |
<= 3.9.19 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
| Root:npm | GitHub Actions | vm2 |
< 3.9.17-aikido.9 Fix: upgrade to 3.9.17-aikido.9
|
Original advisory text
CVE-2023-37903 in vm2 - Patched by Root
Root has patched CVE-2023-37903 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-g644-9gfx-q4q4
- https://nvd.nist.gov/vuln/detail/CVE-2023-37903
- https://security.netapp.com/advisory/ntap-20230831-0007
- https://security.netapp.com/advisory/ntap-20241108-0002
- https://github.com/advisories/GHSA-g644-9gfx-q4q4
- https://security.netapp.com/advisory/ntap-20230831-0007/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20241108-0002/
Severity
10.0
Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 4%
Type
CWE-78OS Command Injection
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta