lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Loading...
Loading...
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
April 22, 2014
May 6, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-4116
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.