DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2019-16776

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2019-16776

CGA ID

CGA-gm4q-336c-9fmr

Severity

8.1

High

CVSS V3

Description

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images