CVE-2017-16206 describes a critical vulnerability in the cofee-script module, where sensitive user data, including private SSH keys and bash history, is exfiltrated to a third-party server during installation. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a severe risk due to its network-based attack vector and low attack complexity, leading to a high impact on confidentiality. Despite its severity, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Furthermore, the CVE has received minimal community discussion or media coverage, suggesting a lack of widespread awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.1CPE matchmatch criteria | cpe:2.3:a:coffescript_project:coffescript:1.0.1:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.