Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-47140: vm2 package can allow unauthorized code execution

CVE-2026-47140 · published 3 days ago
Summary

The vm2 library used in Node.js applications—including those run through GitHub Actions and the @rootio version—has a security weakness that could let an attacker run unwanted code inside the sandbox, potentially affecting the host system or data. This matters because it may let a malicious user break out of the intended isolation. Install the latest patched version of vm2 that includes the fix.

What to do
  • Update GitHub Actions vm2 to version 3.11.4.
  • Update GitHub Actions vm2 to version 3.11.3-aikido.1.
  • Update rootio @rootio/vm2 to version 3.11.3-root.io.1.
  • Update GitHub Actions vm2 to version 3.11.3-aikido.2.
  • Update rootio @rootio/vm2 to version 3.11.3-root.io.2.
  • Update GitHub Actions vm2 to version 3.9.17-aikido.7.
  • Update rootio @rootio/vm2 to version 3.9.17-root.io.7.
  • Update vm2 to version 3.9.17-aikido.10.
  • Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
  • Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
  • Update GitHub Actions vm2 to version 3.9.17-aikido.9.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions vm2 <= 3.11.3
Fix: upgrade to 3.11.4
Root:npm GitHub Actions vm2 < 3.11.3-aikido.1
< 3.11.3-aikido.2
< 3.9.17-aikido.7
< 3.9.17-aikido.9
Fix: upgrade to 3.11.3-aikido.1
Root:npm rootio @rootio/vm2 < 3.11.3-root.io.1
< 3.11.3-root.io.2
< 3.9.17-root.io.7
< 3.9.17-root.io.10
< 3.9.17-root.io.9
Fix: upgrade to 3.11.3-root.io.1
Root:npm – vm2 < 3.9.17-aikido.10
Fix: upgrade to 3.9.17-aikido.10
Original advisory text
CVE-2026-47140 in vm2 - Patched by Root
Root has patched CVE-2026-47140 in the vm2 package for Root:npm. Multiple fixed versions available.
Severity
10.0 Critical
CVSS 3.1: 10.0 (GHSA)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-693Protection Mechanism Failure
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen29 May 2026
Track software like this
Free during beta