Node Packaged Modules Project maintains npm, the package manager for the JavaScript/Node.js ecosystem, and the vulnerability profile reflects the singular focus of this package distribution platform. The durable signal centers on symlink-resolution and file-access weaknesses that arise from the mechanics of package installation and dependency management in a permissive, developer-centric environment. Severity, exploitation status, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Node Packaged Modules Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are creat | Apr 22, 2014 | 3.3 | 12 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Node Packaged Modules Project.
Media articles that mention a CVE ID that affects a product developed by Node Packaged Modules Project — matched by CVE ID, not by vendor name.