Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-27606: Rollup 4 Allows Attackers to Write to Any File on Your Computer

CVE-2026-27606 · published 1 day ago
Summary

If you use Rollup version 4, an attacker could potentially write to any file on your computer that your build process has access to. This could allow them to take control of your system or user settings. To protect yourself, upgrade to a newer version of Rollup and review your plugins to ensure they are safe to use.

What to do
  • Update GitHub Actions rollup to version 2.80.0.
  • Update GitHub Actions rollup to version 3.30.0.
  • Update GitHub Actions rollup to version 4.59.0.
  • Update debian node-rollup to version 3.30.0-1.
  • Update rollup to version 3.29.4-aikido.1.
  • Update rootio @rootio/rollup to version 3.29.4-root.io.1.
  • Update rollup to version 4.37.0-aikido.1.
  • Update rootio @rootio/rollup to version 4.37.0-root.io.1.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions rollup < 2.80.0
>= 3.0.0, < 3.30.0
>= 4.0.0, < 4.59.0
Fix: upgrade to 2.80.0
rollupjs rollup < 2.80.0
>= 3.0.0, < 3.30.0
>= 4.0.0, < 4.59.0
cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:*
Debian:11 debian node-rollup All versions
Debian:12 debian node-rollup All versions
Debian:13 debian node-rollup All versions
Debian:14 debian node-rollup < 3.30.0-1
Fix: upgrade to 3.30.0-1
rollup rollup < 2.80.0
Root:npm rollup < 3.29.4-aikido.1
< 4.37.0-aikido.1
Fix: upgrade to 3.29.4-aikido.1
Root:npm rootio @rootio/rollup < 3.29.4-root.io.1
< 4.37.0-root.io.1
Fix: upgrade to 3.29.4-root.io.1
Original advisory text
CVE-2026-27606 in rollup - Patched by Root
Root has patched CVE-2026-27606 in the rollup package for Root:npm. Multiple fixed versions available.
Severity
9.1 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 8.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 1%
Type
CWE-22Path Traversal
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta