Unauthorized File Access in npm CLI before before version 6.13.3
Published Dec 13, 2019
7.7
HIGHCVSS 3.1
EPSS 3.33%
Description
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Affected products
-
- Version < 6.13.3StatusaffectedConstraints<6.13.3
- Version
Configuration 1
- 8.0
- 8.1
Configuration 4
Configuration 5
- 31
No data.
Red Hat Enterprise Linux 8
nodejs:10-8010020200213140254.c27ad7f8
Fixed · RHSA-2020:0579
Red Hat Enterprise Linux 8
nodejs:12-8010020200116150415.c27ad7f8
Fixed · RHEA-2020:0330
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
nodejs:10-8000020200214110450.f8e95b4e
Fixed · RHSA-2020:0573
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-nodejs-0:8.17.0-2.el7
Fixed · RHSA-2020:2625
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs8-nodejs-0:8.17.0-2.el7
Fixed · RHSA-2020:2625
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs8-nodejs-0:8.17.0-2.el7
Fixed · RHSA-2020:2625
Red Hat OpenShift Application Runtimes
nodejs8
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:10-8010020200213140254.c27ad7f8 | Fixed | RHSA-2020:0579 |
| Red Hat Enterprise Linux 8 | nodejs:12-8010020200116150415.c27ad7f8 | Fixed | RHEA-2020:0330 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nodejs:10-8000020200214110450.f8e95b4e | Fixed | RHSA-2020:0573 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-nodejs-0:8.17.0-2.el7 | Fixed | RHSA-2020:2625 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs8-nodejs-0:8.17.0-2.el7 | Fixed | RHSA-2020:2625 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs8-nodejs-0:8.17.0-2.el7 | Fixed | RHSA-2020:2625 |
| Red Hat OpenShift Application Runtimes | nodejs8 | Out of support scope | n/a |
npm
npm
Introduced 0 Fixed 6.13.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | npm | 0 | 6.13.3 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
2 other sources (GHSA, Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (18 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 3.33% (0.03334) | 88.25th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.27% (0.03266) | 86.74th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.30% (0.00299) | 52.80th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.83% (0.02830) | 84.91th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.39% (0.00392) | 58.13th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.22% (0.00222) | 61.42th | v3 (v2023.03.01) |
| Nov 2, 2023 | 0.19% (0.00186) | 55.67th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.19% (0.00193) | 56.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00238) | 60.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.38% (0.15380) | 92.52th | v2 (v2022.01.01) |
| Feb 3, 2022 | 10.22% (0.10225) | 87.52th | v1 |
| Jan 6, 2022 | 10.22% (0.10225) | 87.37th | v1 |
| Jan 5, 2022 | 2.48% (0.02476) | 79.39th | v5 (v2026.06.15) |
| Oct 21, 2021 | 2.48% (0.02476) | 79.00th | v1 |
| Sep 1, 2021 | 2.27% (0.02273) | 77.89th | v1 |
| Apr 14, 2021 | 2.27% (0.02273) | 0.00th | v1 |
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00027.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHEA-2020:0330 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0573 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0579 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0597 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0602 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-16775 Vendor Advisory
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1788305 Issue Tracking
- https://github.com/advisories/GHSA-m6cx-g6qm-p2cx Advisory
- https://github.com/npm/cli/security/advisories/GHSA-m6cx-g6qm-p2cx x_refsource_CONFIRMThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/
- https://nvd.nist.gov/vuln/detail/CVE-2019-16775
- https://www.cve.org/CVERecord?id=CVE-2019-16775
- https://www.npmjs.com/advisories/1434
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.