VYPR

Node Packaged Modules

by Node Packaged Modules Project

CVEs (1)

  • CVE-2013-4116Apr 22, 2014
    risk 0.00cvss epss 0.00

    lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.