CVE-2017-16076 describes a malicious module named "proxy.js" that was published on npm with the intent to hijack environment variables, affecting the proxy.js_project. This vulnerability carries a CVSS v3.0 score of 7.5 (HIGH), indicating a network-based attack with low complexity that could lead to high confidentiality impact without requiring user interaction. While the module has been unpublished and there are no known public exploits, Metasploit modules, or Nuclei templates, the vulnerability's potential for data exposure warrants attention. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:proxy.js_project:proxy.js:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.