Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-43999: vm2 packages could let attackers run code
CVE-2026-43999 · published 2 days ago
Summary
The vm2 library used in several GitHub and npm projects can be tricked into executing unwanted code. This could let a malicious user take control of your system or data. Update to the latest patched versions of vm2 as soon as possible to protect your environment.
What to do
- Update GitHub Actions vm2 to version 3.11.0.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.3.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.4.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.5.
- Update GitHub Actions vm2 to version 3.10.5-aikido.6.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.6.
- Update vm2 to version 3.10.5-aikido.7.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.7.
- Update vm2 to version 3.10.5-aikido.8.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.8.
- Update vm2_project vm2 to version 3.11.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | vm2 |
3.10.5 Fix: upgrade to 3.11.0
|
| Root:npm | rootio | @rootio/vm2 |
< 3.10.5-root.io.3 < 3.10.5-root.io.4 < 3.10.5-root.io.5 < 3.10.5-root.io.6 < 3.10.5-root.io.7 < 3.10.5-root.io.8 Fix: upgrade to 3.10.5-root.io.3
|
| Root:npm | GitHub Actions | vm2 |
< 3.10.5-aikido.6 Fix: upgrade to 3.10.5-aikido.6
|
| – | patriksimek | vm2 | < 3.11.0 |
| – | vm2_project | vm2 |
< 3.11.0 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
| Root:npm | – | vm2 |
< 3.10.5-aikido.7 < 3.10.5-aikido.8 Fix: upgrade to 3.10.5-aikido.7
|
Original advisory text
CVE-2026-43999 in vm2 - Patched by Root
Root has patched CVE-2026-43999 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://github.com/advisories/GHSA-947f-4v7f-x2v8
- https://nvd.nist.gov/vuln/detail/CVE-2026-43999
- https://github.com/patriksimek/vm2/security/advisories/GHSA-947f-4v7f-x2v8 Exploit Mitigation Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50850
- https://access.redhat.com/security/cve/CVE-2026-43999
- https://bugzilla.redhat.com/show_bug.cgi?id=2477196
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43999.json
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-863Incorrect Authorization
CWE-829Inclusion of Functionality from Untrusted Control Sphere
Timeline
Published8 Oct 2026
Updated8 Oct 2026
First seen7 May 2026
Track software like this
Free during beta