Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-44008: vm2 package could allow unauthorized code execution
CVE-2026-44008 · published 3 days ago
Summary
The vm2 software used in several projects can be tricked into running malicious code, which could let attackers take control of the system. Updated versions have been released that fix this weakness. Apply the latest vm2 version as soon as possible to protect your environment.
What to do
- Update GitHub Actions vm2 to version 3.11.2.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.5.
- Update GitHub Actions vm2 to version 3.10.5-aikido.6.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.6.
- Update GitHub Actions vm2 to version 3.9.17-aikido.7.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.7.
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
- Update GitHub Actions vm2 to version 3.9.17-aikido.9.
- Update vm2_project vm2 to version 3.11.2 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | vm2 |
<= 3.11.1 Fix: upgrade to 3.11.2
|
| Root:npm | rootio | @rootio/vm2 |
< 3.10.5-root.io.5 < 3.10.5-root.io.6 < 3.9.17-root.io.7 < 3.9.17-root.io.10 < 3.9.17-root.io.9 Fix: upgrade to 3.10.5-root.io.5
|
| Root:npm | GitHub Actions | vm2 |
< 3.10.5-aikido.6 < 3.9.17-aikido.7 < 3.9.17-aikido.9 Fix: upgrade to 3.10.5-aikido.6
|
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 Fix: upgrade to 3.9.17-aikido.10
|
| – | patriksimek | vm2 | < 3.11.2 |
| – | vm2_project | vm2 |
< 3.11.2 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
Original advisory text
CVE-2026-44008 in vm2 - Patched by Root
Root has patched CVE-2026-44008 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-44008
- https://github.com/patriksimek/vm2/security/advisories/GHSA-9qj6-qjgg-37qq x_refsource_CONFIRM
- https://github.com/advisories/GHSA-9qj6-qjgg-37qq
- https://access.redhat.com/errata/RHSA-2026:50850
- https://access.redhat.com/security/cve/CVE-2026-44008
- https://bugzilla.redhat.com/show_bug.cgi?id=2477201
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44008.json
- https://github.com/patriksimek/vm2/releases/tag/v3.11.2
Severity
9.8
Critical
CVSS 3.1: 9.8 (GHSA)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-668Exposure of Resource to Wrong Sphere
CWE-1100Insufficient Isolation of System-Dependent Functions
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen8 May 2026
Track software like this
Free during beta