Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
2019-12-13T01:15:10.913
2024-11-21T04:31:10.063
Modified
CVSSv3.1: 7.7 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | npmjs | npm | < 6.13.3 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Application | oracle | graalvm | 19.3.0.2 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux_eus | 8.1 | Yes |