VYPR

Node Tmp

by Raszi

Source repositories

CVEs (1)

  • CVE-2026-44705higMay 27, 2026
    risk 0.38cvss epss

    ### Summary The tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the `prefix`, `postfix`, or `dir` options. By embedding traversal sequences (e.g., `../`) or path separators in these…