Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-44006: vm2 could let attackers execute code
CVE-2026-44006 · published 3 days ago
Summary
The vm2 library used in several projects can be tricked into running unwanted code, which could let an attacker take control of a system. This risk has been fixed in newer releases of vm2, including the versions provided by Root and other repositories. Update vm2 to the latest patched version as soon as possible to stay protected.
What to do
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update GitHub Actions vm2 to version 3.11.0.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.3.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.4.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.5.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.6.
- Update GitHub Actions vm2 to version 3.10.5-aikido.6.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.7.
- Update GitHub Actions vm2 to version 3.9.17-aikido.7.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
- Update GitHub Actions vm2 to version 3.9.17-aikido.9.
- Update vm2_project vm2 to version 3.11.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 Fix: upgrade to 3.9.17-aikido.10
|
| Root:npm | rootio | @rootio/vm2 |
< 3.9.17-root.io.10 < 3.10.5-root.io.3 < 3.10.5-root.io.4 < 3.10.5-root.io.5 < 3.10.5-root.io.6 < 3.9.17-root.io.7 < 3.9.17-root.io.9 Fix: upgrade to 3.9.17-root.io.10
|
| npm | GitHub Actions | vm2 |
<= 3.10.5 Fix: upgrade to 3.11.0
|
| Root:npm | GitHub Actions | vm2 |
< 3.10.5-aikido.6 < 3.9.17-aikido.7 < 3.9.17-aikido.9 Fix: upgrade to 3.10.5-aikido.6
|
| – | patriksimek | vm2 | < 3.11.0 |
| – | vm2_project | vm2 |
< 3.11.0 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
Original advisory text
CVE-2026-44006 in vm2 - Patched by Root
Root has patched CVE-2026-44006 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://github.com/patriksimek/vm2/blob/408fc855f1cc1bbc2985b029465ee0e732ada433...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.0
- https://github.com/advisories/GHSA-qcp4-v2jj-fjx8
- https://nvd.nist.gov/vuln/detail/CVE-2026-44006
- https://github.com/patriksimek/vm2/security/advisories/GHSA-qcp4-v2jj-fjx8 x_refsource_CONFIRM
- https://access.redhat.com/errata/RHSA-2026:50850
- https://access.redhat.com/security/cve/CVE-2026-44006
- https://bugzilla.redhat.com/show_bug.cgi?id=2477200
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44006.json
Severity
10.0
Critical
CVSS 3.1: 10.0 (GHSA)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
CWE-914Improper Control of Dynamically-Identified Variables
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen7 May 2026
Track software like this
Free during beta