Lima VM Vulnerability: Arbitrary User Could Gain Root Privilege
- Severity
- HIGH
- Affected component
- lima (github-actions)
- Patched version
- 2.1.3
An arbitrary user in a QEMU VM could reportedly gain root privileges via the guest agent socket in Lima versions <=2.1.2.
What happened
An early warning has been issued regarding a vulnerability in Lima VM. According to the advisory, an arbitrary user within a QEMU VM could gain root privileges via the guest agent socket. This issue has been patched in Lima version 2.1.3. The vulnerability was first flagged on 2026-08-14T19:24:33+00:00. The advisory recommends upgrading to Lima version 2.1.3 or higher to mitigate the risk.
The vulnerability affects Lima VM versions up to and including 2.1.2. The patched version is 2.1.3. The advisory does not indicate that this vulnerability has been exploited in the wild. Users are advised to consult the primary sources for the most current information and to upgrade their installations as soon as possible.
What to do about it
- Identify the version of Lima VM currently in use.
- If the version is <=2.1.2, upgrade to Lima VM version 2.1.3 or higher.
- Verify the upgrade by checking the version post-installation.
- Monitor the primary sources for any updates or additional advisories related to this vulnerability.
How 0Day would have caught this
lima is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using Lima VM version <=2.1.2.
What should I do right now?
Upgrade your Lima VM to version 2.1.3 or higher.
Has this vulnerability been exploited in the wild?
The primary sources do not indicate that this vulnerability has been exploited in the wild.