Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-47208: vm2 package may let attackers run code
CVE-2026-47208 · published 3 days ago
Summary
The vm2 library used in GitHub Actions, rootio/@rootio, and other projects can be tricked into executing unwanted code. This could let a malicious user take control of the system that runs the software. Update vm2 to the newest released version as soon as possible to protect against this risk.
What to do
- Update GitHub Actions vm2 to version 3.11.4.
- Update GitHub Actions vm2 to version 3.11.3-aikido.1.
- Update rootio @rootio/vm2 to version 3.11.3-root.io.1.
- Update GitHub Actions vm2 to version 3.11.3-aikido.2.
- Update rootio @rootio/vm2 to version 3.11.3-root.io.2.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.7.
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update GitHub Actions vm2 to version 3.9.17-aikido.9.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
- Update GitHub Actions vm2 to version 3.9.17-aikido.7.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | vm2 |
<= 3.11.3 Fix: upgrade to 3.11.4
|
| Root:npm | GitHub Actions | vm2 |
< 3.11.3-aikido.1 < 3.11.3-aikido.2 < 3.9.17-aikido.9 < 3.9.17-aikido.7 Fix: upgrade to 3.11.3-aikido.1
|
| Root:npm | rootio | @rootio/vm2 |
< 3.11.3-root.io.1 < 3.11.3-root.io.2 < 3.9.17-root.io.7 < 3.9.17-root.io.10 < 3.9.17-root.io.9 Fix: upgrade to 3.11.3-root.io.1
|
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 Fix: upgrade to 3.9.17-aikido.10
|
Original advisory text
CVE-2026-47208 in vm2 - Patched by Root
Root has patched CVE-2026-47208 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-76w7-j9cq-rx2j
- https://github.com/patriksimek/vm2/commit/a462655009669c3124ee39498121651597529e...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.4
- https://github.com/advisories/GHSA-76w7-j9cq-rx2j
- https://nvd.nist.gov/vuln/detail/CVE-2026-47208
Severity
10.0
Critical
CVSS 3.1: 10.0 (GHSA)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen29 May 2026
Track software like this
Free during beta