VendorsNpmjsnpmall versions
Vulnerabilities

Npmjs Npm

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2021-43616
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.
Published 2021-11-13 · Modified
9.8EPSS 0.026
CVE-2021-39134
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
Published 2021-08-31 · Modified
8.2EPSS 0.006
CVE-2021-39135
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
Published 2021-08-31 · Modified
8.2EPSS 0.006
CVE-2019-16776
Unauthorized File Access in npm CLI before before version 6.13.3
Published 2019-12-13 · Modified
8.1EPSS 0.034
CVE-2018-7408
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's blog without mention of pre-release status). It might allow local users to bypass intended filesystem access restrictions because ownerships of /etc and /usr directories are being changed unexpectedly, related to a "correctMkdir" issue.
Published 2018-02-22 · Modified
7.8EPSS 0.003
CVE-2019-16775
Unauthorized File Access in npm CLI before before version 6.13.3
Published 2019-12-13 · Modified
7.7EPSS 0.033
CVE-2019-16777
Arbitrary File Overwrite in npm CLI
Published 2019-12-13 · Modified
7.7EPSS 0.020
CVE-2016-3956
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
Published 2016-07-02 · Modified
7.5EPSS 0.067
CVE-2022-29244
npm packing does not respect root-level ignore files in workspaces
Published 2022-06-13 · Modified
7.5EPSS 0.039
CVE-2020-15095
Sensitive information exposure through logs in npm cli
Published 2020-07-07 · Modified
4.4EPSS 0.004