VendorsNpmjsnpmany version
Vulnerabilities

Npmjs Npm any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-43616
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.
Published 2021-11-13 · Modified
9.8EPSS 0.026
CVE-2021-39134
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
Published 2021-08-31 · Modified
8.2EPSS 0.006
CVE-2021-39135
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
Published 2021-08-31 · Modified
8.2EPSS 0.006
CVE-2019-16776
Unauthorized File Access in npm CLI before before version 6.13.3
Published 2019-12-13 · Modified
8.1EPSS 0.034
CVE-2019-16775
Unauthorized File Access in npm CLI before before version 6.13.3
Published 2019-12-13 · Modified
7.7EPSS 0.033
CVE-2019-16777
Arbitrary File Overwrite in npm CLI
Published 2019-12-13 · Modified
7.7EPSS 0.020
CVE-2016-3956
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
Published 2016-07-02 · Modified
7.5EPSS 0.067
CVE-2022-29244
npm packing does not respect root-level ignore files in workspaces
Published 2022-06-13 · Modified
7.5EPSS 0.039
CVE-2020-15095
Sensitive information exposure through logs in npm cli
Published 2020-07-07 · Modified
4.4EPSS 0.004