Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-45411: vm2 package lets attackers run unwanted code

CVE-2026-45411 · published 3 days ago
Summary

The vm2 library used in several GitHub Actions and npm projects can be tricked into executing code it shouldn't. This could let a malicious user run commands on your system through the affected applications. Update to the latest released versions of vm2 to protect your environment.

What to do
  • Update GitHub Actions vm2 to version 3.11.3.
  • Update rootio @rootio/vm2 to version 3.11.3-root.io.3.
  • Update GitHub Actions vm2 to version 3.11.3-aikido.3.
  • Update vm2 to version 3.9.17-aikido.10.
  • Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
  • Update vm2_project vm2 to version 3.11.3 or later.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions vm2 <= 3.11.2
Fix: upgrade to 3.11.3
Root:npm rootio @rootio/vm2 < 3.11.3-root.io.3
< 3.9.17-root.io.10
Fix: upgrade to 3.11.3-root.io.3
Root:npm GitHub Actions vm2 < 3.11.3-aikido.3
Fix: upgrade to 3.11.3-aikido.3
– patriksimek vm2 < 3.11.3
Root:npm – vm2 < 3.9.17-aikido.10
Fix: upgrade to 3.9.17-aikido.10
– vm2_project vm2 < 3.11.3
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Original advisory text
CVE-2026-45411 in vm2 - Patched by Root
Root has patched CVE-2026-45411 in the vm2 package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-668Exposure of Resource to Wrong Sphere
CWE-237Improper Handling of Structural Elements
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen13 May 2026
Track software like this
Free during beta