CVE-2019-16776
ADVISORY - githubSummary
Versions of the npm CLI prior to 6.13.3 are vulnerable to a symlink reference outside of node_modules. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user’s system when the package is installed. Only files accessible by the user running the npm install are affected.
This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Recommendation
Upgrade to version 6.13.3 or later.
Common Weakness Enumeration (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Input Validation
NIST
1.3
CVSS SCORE
7.7highGitHub
1.3
CVSS SCORE
7.7highDebian
-
Ubuntu
2.8
CVSS SCORE
8.1mediumAlma
-
CVSS SCORE
N/AhighRed Hat
1.2
CVSS SCORE
4.8lowRocky
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighChainguard
CGA-2427-32qv-5x85
-
Chainguard
CGA-33fr-9p8c-q625
-
Chainguard
CGA-46fx-37c8-2pmf
-
Chainguard
CGA-4g2v-q782-wxq4
-
Chainguard
CGA-4hf6-7g95-xfjc
-
Chainguard
CGA-63q3-g3gw-prcw
-
Chainguard
CGA-74fh-wmp2-g5r8
-
Chainguard
CGA-7r52-gvrc-c3pv
-
Chainguard
CGA-89v2-qm8v-rq42
-
Chainguard
CGA-8hpp-xp85-wwfg
-
Chainguard
CGA-969f-6cw9-xh59
-
Chainguard
CGA-9pmg-643m-hw63
-
Chainguard
CGA-c427-mc9w-gh8m
-
Chainguard
CGA-cvp5-r4vq-f74m
-
Chainguard
CGA-f83r-hf7q-6c4p
-
Chainguard
CGA-fg8j-7qvr-3xj8
-
Chainguard
CGA-fv7g-cr6r-p3cf
-
Chainguard
CGA-gh3r-554m-2q74
-
Chainguard
CGA-ghwg-5g6q-g8p2
-
Chainguard
CGA-gm4q-336c-9fmr
-
Chainguard
CGA-gv6p-79m2-m7xm
-
Chainguard
CGA-h6mm-74w8-8j8h
-
Chainguard
CGA-hmq4-gm5h-hpvw
-
Chainguard
CGA-j7g7-g38x-vwr4
-
Chainguard
CGA-jcc8-hxp7-3m6g
-
Chainguard
CGA-jffg-qjr2-vv8r
-
Chainguard
CGA-m78g-5rxq-8j78
-
Chainguard
CGA-m7v4-vg34-5f5r
-
Chainguard
CGA-q4vr-pr45-p94h
-
Chainguard
CGA-r3g7-q8r6-2wwh
-
Chainguard
CGA-r4jc-9xg3-434g
-
Chainguard
CGA-rp95-g4p9-34gx
-
Chainguard
CGA-v37g-xh3f-2mmr
-
Chainguard
CGA-w94j-xp53-86fc
-
Chainguard
CGA-w95c-6889-6xm2
-
Chainguard
CGA-wmfh-m9v9-x2xf
-
Chainguard
CGA-xjxm-8pp6-cv4v
-