Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-24120: vm2 package can run unwanted code on your system
CVE-2026-24120 · published 11 days ago
Summary
The vm2 library used in several GitHub Actions and npm packages can let attackers execute code on the host machine. This risk applies to vm2, vm2_project/vm2, rootio/@rootio/vm2, patriksimek/vm2, and GitHub Actions/vm2. Update all these packages to the latest released versions as soon as possible.
What to do
- Update GitHub Actions vm2 to version 3.10.5.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.6.
- Update GitHub Actions vm2 to version 3.10.5-aikido.6.
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update vm2 to version 3.9.7-aikido.5.
- Update rootio @rootio/vm2 to version 3.9.7-root.io.5.
- Update vm2 to version 3.9.7-aikido.6.
- Update rootio @rootio/vm2 to version 3.9.7-root.io.6.
- Update vm2_project vm2 to version 3.10.5 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | vm2 |
<= 3.10.3 Fix: upgrade to 3.10.5
|
| Root:npm | rootio | @rootio/vm2 |
< 3.10.5-root.io.6 < 3.9.17-root.io.10 < 3.9.7-root.io.5 < 3.9.7-root.io.6 Fix: upgrade to 3.10.5-root.io.6
|
| Root:npm | GitHub Actions | vm2 |
< 3.10.5-aikido.6 Fix: upgrade to 3.10.5-aikido.6
|
| – | patriksimek | vm2 | < 3.10.5 |
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 < 3.9.7-aikido.5 < 3.9.7-aikido.6 Fix: upgrade to 3.9.17-aikido.10
|
| – | vm2_project | vm2 |
< 3.10.5 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
Original advisory text
CVE-2026-24120 in vm2 - Patched by Root
Root has patched CVE-2026-24120 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://github.com/patriksimek/vm2/releases/tag/v3.10.5 Release Notes
- https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5
- https://nvd.nist.gov/vuln/detail/CVE-2026-24120
- https://github.com/advisories/GHSA-qvjj-29qf-hp7p
- https://access.redhat.com/security/cve/CVE-2026-24120
- https://bugzilla.redhat.com/show_bug.cgi?id=2466529
- https://github.com/patriksimek/vm2/security/advisories/GHSA-qvjj-29qf-hp7p Exploit Vendor Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24120.json
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-94Code Injection
CWE-693Protection Mechanism Failure
CWE-807Reliance on Untrusted Inputs in a Security Decision
Timeline
Published30 Sep 2026
Updated7 Oct 2026
First seen4 May 2026
Track software like this
Free during beta