Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
CVSS Details
- CVSS 3.1 Base Score: 7.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nodejs-nodemonUpgrade nodejs-packaging | May 4, 2022 | Dec 13, 2019 |
| Centos_linux | — | Upgrade npmUpgrade nodejs-develUpgrade nodejs-debuginfoUpgrade nodejs-nodemonUpgrade nodejs-debugsourceUpgrade nodejs-devel-debuginfoUpgrade nodejs-packagingUpgrade nodejs-docsUpgrade nodejs | Feb 26, 2020 | Dec 13, 2019 |
| Debian | — | Upgrade npm | Jul 30, 2024 | Dec 13, 2019 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jul 3, 2026 | Jul 2, 2026 |
| Freebsd | — | Upgrade npm | Jun 11, 2020 | Jun 10, 2020 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | Mar 23, 2020 | Dec 13, 2019 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-10 to version 10.19.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade runtime/nodejs to version 8.17.0-11.4.18.0.1.2.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-8 to version 8.17.0-11.4.18.0.1.2.0 on Solaris 11.4 | Jan 19, 2021 | Dec 13, 2019 |
| Oracle_linux | — | Upgrade npmUpgrade nodejsUpgrade nodejs-develUpgrade nodejs-docsUpgrade nodejs-nodemonUpgrade nodejs-packaging | Mar 2, 2020 | Dec 12, 2019 |
| Redhat_linux | — | Upgrade nodejs-debuginfoUpgrade nodejs-debugsourceUpgrade nodejs-packagingUpgrade npmUpgrade nodejs-develUpgrade nodejs-nodemonUpgrade nodejs-docsUpgrade nodejsUpgrade nodejs-devel-debuginfo | Feb 26, 2020 | Dec 13, 2019 |
| Rocky_linux | — | — | Aug 15, 2024 | Dec 13, 2019 |
| Suse | — | Upgrade nodejs8Upgrade npm10Upgrade npm12Upgrade nodejs12-docsUpgrade nodejs10-docsUpgrade nodejs10-develUpgrade nodejs8-docsUpgrade nodejs12-develUpgrade npm6Upgrade nodejs12Upgrade nodejs6Upgrade nodejs10Upgrade nodejs6-develUpgrade npm8Upgrade nodejs6-docsUpgrade nodejs8-devel | Jan 16, 2020 | Dec 13, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub