Npm

Vendor:

First CVE: Jul 2, 2016 · Active for 10 years

10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Npm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2016
10 years ago
Most Recent CVE
Jun 13, 2022
1,503 days ago

CVE Severity & Scoring

Npm10 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local4 (40.0%)
Network6 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low5 (50.0%)
High0 (0.0%)
None5 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is in
Nov 13, 20219.833NONO
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone
Jun 13, 20227.527NONO
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin
Dec 13, 20198.127NONO
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arb
Jul 2, 20167.527NONO
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package de
Aug 31, 20217.826NONO
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package
Aug 31, 20217.825NONO
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced
Feb 22, 20187.825NONO
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through
Dec 13, 20196.524NONO
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package i
Dec 13, 20196.522NONO
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<h
Jul 7, 20204.414NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Npm

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.7.017.80.3%00