Critical severity9.8NVD Advisory· Published Mar 3, 2022· Updated Jun 17, 2026
CVE-2022-0841
CVE-2022-0841
Description
OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
npm-lockfilenpm | >= 2.0.3, < 2.0.5 | 2.0.5 |
Affected products
4cpe:2.3:a:npm-lockfile_project:npm-lockfile:2.0.3:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:npm-lockfile_project:npm-lockfile:2.0.3:*:*:*:*:node.js:*:*
- cpe:2.3:a:npm-lockfile_project:npm-lockfile:2.0.4:*:*:*:*:node.js:*:*
- ljharb/ljharb/npm-lockfilev5Range: 2.0.3
Patches
Vulnerability mechanics
References
4- github.com/ljharb/npm-lockfile/commit/bfdb84813260f0edbf759f2fde1e8c816c1478b8nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/4f806dc9-2ecd-4e79-997e-5292f1bea9f1nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-cr6m-62pq-hmqhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-0841ghsaADVISORY
News mentions
0No linked articles in our index yet.