VYPR

Chownr

by Chownr Project

Source repositories

CVEs (1)

  • CVE-2017-18869LowJun 15, 2020
    risk 0.09cvss 2.5epss 0.00

    A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.