Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-27606: Rollup 4 Allows Attackers to Write to Any File on Your Computer
CVE-2026-27606 · published 1 day ago
Summary
If you use Rollup version 4, an attacker could potentially write to any file on your computer that your build process has access to. This could allow them to take control of your system or user settings. To protect yourself, upgrade to a newer version of Rollup and review your plugins to ensure they are safe to use.
What to do
- Update GitHub Actions rollup to version 2.80.0.
- Update GitHub Actions rollup to version 3.30.0.
- Update GitHub Actions rollup to version 4.59.0.
- Update debian node-rollup to version 3.30.0-1.
- Update rollup to version 3.29.4-aikido.1.
- Update rootio @rootio/rollup to version 3.29.4-root.io.1.
- Update rollup to version 4.37.0-aikido.1.
- Update rootio @rootio/rollup to version 4.37.0-root.io.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | rollup |
< 2.80.0 >= 3.0.0, < 3.30.0 >= 4.0.0, < 4.59.0 Fix: upgrade to 2.80.0
|
| – | rollupjs | rollup |
< 2.80.0 >= 3.0.0, < 3.30.0 >= 4.0.0, < 4.59.0 cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:* |
| Debian:11 | debian | node-rollup | All versions |
| Debian:12 | debian | node-rollup | All versions |
| Debian:13 | debian | node-rollup | All versions |
| Debian:14 | debian | node-rollup |
< 3.30.0-1 Fix: upgrade to 3.30.0-1
|
| – | rollup | rollup | < 2.80.0 |
| Root:npm | – | rollup |
< 3.29.4-aikido.1 < 4.37.0-aikido.1 Fix: upgrade to 3.29.4-aikido.1
|
| Root:npm | rootio | @rootio/rollup |
< 3.29.4-root.io.1 < 4.37.0-root.io.1 Fix: upgrade to 3.29.4-root.io.1
|
Original advisory text
CVE-2026-27606 in rollup - Patched by Root
Root has patched CVE-2026-27606 in the rollup package for Root:npm. Multiple fixed versions available.
References
- https://github.com/rollup/rollup/commit/d6dee5e99bb82aac0bee1df4ab9efbde455452c3 Patch
- https://github.com/rollup/rollup/releases/tag/v2.80.0 Product
- https://security-tracker.debian.org/tracker/CVE-2026-27606 Vendor Advisory
- https://github.com/rollup/rollup/releases/tag/v3.30.0 Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-27606
- https://github.com/advisories/GHSA-mw96-cpmx-2vgc
- https://github.com/rollup/rollup/commit/c60770d7aaf750e512c1b2774989ea4596e660b2 Patch
- https://github.com/rollup/rollup/commit/c8cf1f9c48c516285758c1e11f08a54f304fd44e Patch
- https://github.com/rollup/rollup/releases/tag/v4.59.0 Product
- https://github.com/rollup/rollup/security/advisories/GHSA-mw96-cpmx-2vgc Exploit Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27606... Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:10175
- https://access.redhat.com/errata/RHSA-2026:13508
- https://access.redhat.com/errata/RHSA-2026:13512
- https://access.redhat.com/errata/RHSA-2026:13545
- https://access.redhat.com/errata/RHSA-2026:5132
- https://access.redhat.com/errata/RHSA-2026:5649
- https://access.redhat.com/errata/RHSA-2026:5665
- https://access.redhat.com/errata/RHSA-2026:6174
- https://access.redhat.com/errata/RHSA-2026:6802
- https://access.redhat.com/errata/RHSA-2026:8483
- https://access.redhat.com/security/cve/CVE-2026-27606
- https://bugzilla.redhat.com/show_bug.cgi?id=2442530
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27606.json
Severity
9.1
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 8.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 1%
Type
CWE-22Path Traversal
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen6 Mar 2026
Sources
DEBIAN-CVE-2026-27606 · OSV
CVE-2026-27606 · NVD
GHSA-mw96-cpmx-2vgc · GHSA
CVE-2026-27606 · OSV
CVE-2026-27606 · MITRE
Monitor software like this
Free during beta