cbcvebase.
CVE-2019-16775
published 2019-12-13

CVE-2019-16775: Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of…

PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
3.27%
87.0th percentile
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiannpm< npm 6.13.4+ds-2 (bookworm)npm 6.13.4+ds-2 (bookworm)
fedoraprojectfedora
npmcli< 6.13.36.13.3
npmjsnpm< 6.13.36.13.3
npmjsnpm>= 0 < 6.13.4+ds-26.13.4+ds-2
npmjsnpm>= 0 < 6.13.4+ds-26.13.4+ds-2
npmjsnpm>= 0 < 6.13.4+ds-26.13.4+ds-2
npmjsnpm>= 0 < 6.13.4+ds-26.13.4+ds-2
npmjsnpm>= 0 < 6.13.36.13.3
opensuseleap
oraclegraalvm
oraclegraalvm
oraclegraalvm
redhatenterprise_linux
redhatenterprise_linux_eus

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.