Rollup is a widely used JavaScript module bundler. Upstream and advisory database sources identify CVE-2026-27606 / GHSA-mw96-cpmx-2vgc as a path-traversal file-write issue in affected rollup release lines before 2.80.0, 3.30.0, and 4.59.0 [S1][S2][S3].
Impact
Projects that build attacker-influenced modules, chunk names, or plugin-provided output names with an affected Rollup version may be exposed to writes outside the intended build output area [S1][S2]. The practical impact depends on how the build pipeline is invoked, which inputs and plugins are trusted, and what filesystem permissions the developer workstation or CI runner grants to the build process.
Root Cause
The affected Rollup release lines did not fully constrain certain generated output names to the intended build directory before writing files [S1][S2]. That made the package vulnerable when untrusted build-time names reached the vulnerable path-handling logic.
How FixVibe covers it
FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve rollup to a version in the affected advisory ranges, with the file and the fixed release for your major line.
Fix
Upgrade every direct or transitive rollup dependency so the active lockfile resolves to a fixed release for the major line in use:
- 2.80.0 or newer for Rollup 2.x
- 3.30.0 or newer for Rollup 3.x
- 4.59.0 or newer for Rollup 4.x
Regenerate the lockfile from a clean install, review Vite/Rollup/plugin configuration for untrusted build-time names, and rerun the FixVibe repo scan after the package graph resolves to a fixed version.
