Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-45411: vm2 package lets attackers run unwanted code
CVE-2026-45411 · published 3 days ago
Summary
The vm2 library used in several GitHub Actions and npm projects can be tricked into executing code it shouldn't. This could let a malicious user run commands on your system through the affected applications. Update to the latest released versions of vm2 to protect your environment.
What to do
- Update GitHub Actions vm2 to version 3.11.3.
- Update rootio @rootio/vm2 to version 3.11.3-root.io.3.
- Update GitHub Actions vm2 to version 3.11.3-aikido.3.
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update vm2_project vm2 to version 3.11.3 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | vm2 |
<= 3.11.2 Fix: upgrade to 3.11.3
|
| Root:npm | rootio | @rootio/vm2 |
< 3.11.3-root.io.3 < 3.9.17-root.io.10 Fix: upgrade to 3.11.3-root.io.3
|
| Root:npm | GitHub Actions | vm2 |
< 3.11.3-aikido.3 Fix: upgrade to 3.11.3-aikido.3
|
| – | patriksimek | vm2 | < 3.11.3 |
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 Fix: upgrade to 3.9.17-aikido.10
|
| – | vm2_project | vm2 |
< 3.11.3 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
Original advisory text
CVE-2026-45411 in vm2 - Patched by Root
Root has patched CVE-2026-45411 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://access.redhat.com/errata/RHSA-2026:50850
- https://access.redhat.com/security/cve/CVE-2026-45411
- https://bugzilla.redhat.com/show_bug.cgi?id=2477210
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45411.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-45411
- https://github.com/patriksimek/vm2/commit/093494c0c3ef2390d2e56909f9d56e290e6f18...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.3
- https://github.com/advisories/GHSA-248r-7h7q-cr24
- https://github.com/patriksimek/vm2/security/advisories/GHSA-248r-7h7q-cr24 Exploit Vendor Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-668Exposure of Resource to Wrong Sphere
CWE-237Improper Handling of Structural Elements
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen13 May 2026
Track software like this
Free during beta