Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27606

37
FAUCET Score

CVE-2026-27606 describes a critical path traversal vulnerability in the Rollup JavaScript module bundler, affecting versions prior to 2.80.0, 3.30.0, and 4.59.0. This flaw allows attackers to control output filenames, using traversal sequences to write arbitrary files anywhere on the host filesystem with the build process's permissions. With a CVSS score of 9.8 (Critical), the vulnerability has a low attack complexity and no user interaction required, potentially leading to persistent Remote Code Execution (RCE) by overwriting critical system files. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, including a detailed article on Dev.to.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.80.0CPE matchmatch criteria
cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:*
>= 3.0.0, < 3.30.0CPE matchmatch criteria
cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:*
>= 4.0.0, < 4.59.0CPE matchmatch criteria
cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.40%
Probability of exploitation in next 30 days
EPSS Percentile
69.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0140 is in the 56th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (36)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: rollupFixed in: 2.80.0
npmpatch availablevia ghsa
Product: rollupFixed in: 3.30.0
npmpatch availablevia ghsa
Product: rollupFixed in: 4.59.0
redhatno patchvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: org.jolokia-jolokia-parent
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/gateway-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-on-clouds/aoc-azure-aap-installer-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-eda-controller
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-gateway
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-platform-ui
redhatno patchvia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: org.optaweb.vehiclerouting-optaweb-vehicle-routing
redhatno patchvia redhat_api
Product: Red Hat Build of Podman Desktop - Tech PreviewFixed in: rhdesktop/rh-podman-desktop-ext-bootc-rhel10
redhatno patchvia redhat_api
Product: Red Hat Build of Podman Desktop - Tech PreviewFixed in: rhdesktop/rh-podman-desktop-ext-openshift-local-rhel10
redhatno patchvia redhat_api
Product: Red Hat Build of Podman Desktop - Tech PreviewFixed in: rhdesktop/rh-podman-desktop-ext-redhat-account-rhel10
redhatno patchvia redhat_api
Product: Red Hat Build of Podman Desktop - Tech PreviewFixed in: rhdesktop/rh-podman-desktop-ext-rhel-rhel10
redhatno patchvia redhat_api
Product: Red Hat Build of Podman Desktop - Tech PreviewFixed in: rhdesktop/rh-podman-desktop-ext-sandbox-rhel10
redhatno patchvia redhat_api
Product: Red Hat Developer HubFixed in: rhdh/rhdh-hub-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: grafana
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-api-rhel8
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs
redhatno patchvia redhat_api
Product: Red Hat Fuse 7Fixed in: io.syndesis-syndesis-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.keycloak-keycloak-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.keycloak-keycloak-parent
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-agent-installer-ui-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/traefik-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/tempo-jaeger-query-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: org.keycloak-keycloak-parent
redhatno patchvia redhat_api
Product: Red Hat Trusted Artifact SignerFixed in: rhtas/rhtas-console-ui-rhel9
redhatno patchvia redhat_api
Product: Self-service automation portal 2Fixed in: ansible-automation-platform/automation-portal
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-db-migration-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-ui-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8

Vendor Advisories (2)

npmGHSA-mw96-cpmx-2vgchigh

Rollup 4 has Arbitrary File Write via Path Traversal

Feb 25, 2026
redhatCVE-2026-27606Important

rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability

Feb 25, 2026

References

access.redhat.com / errata/RHSA-2026:10175
access.redhat.com / errata/RHSA-2026:13508
access.redhat.com / errata/RHSA-2026:13512
access.redhat.com / errata/RHSA-2026:13545
access.redhat.com / errata/RHSA-2026:5132
access.redhat.com / errata/RHSA-2026:5649
access.redhat.com / errata/RHSA-2026:5665
access.redhat.com / errata/RHSA-2026:6174
access.redhat.com / errata/RHSA-2026:6802
access.redhat.com / errata/RHSA-2026:8483
access.redhat.com / security/cve/CVE-2026-27606
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-27606.json
github.com / rollup/rollup/commit/c60770d7aaf750e512c1b2774989ea4596e660b2
Patch
github.com / rollup/rollup/commit/c8cf1f9c48c516285758c1e11f08a54f304fd44e
Patch
github.com / rollup/rollup/commit/d6dee5e99bb82aac0bee1df4ab9efbde455452c3
Patch
github.com / rollup/rollup/releases/tag/v2.80.0
Product
github.com / rollup/rollup/releases/tag/v3.30.0
Product
github.com / rollup/rollup/releases/tag/v4.59.0
Product
github.com / rollup/rollup/security/advisories/GHSA-mw96-cpmx-2vgc
ExploitVendor Advisory