Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Secfathy

#43819of 57,427
6.7Total CVSS
Vulnerabilities · 1
PT-2026-96035
6.7
2026-09-21
Nvm · Nvm · CVE-2026-94185
**Name of the Vulnerable Software and Affected Versions** nvm versions prior to 0.40.8 **Description** The `nvm alias()` function fails to perform a containment check when concatenating a requested version or alias name to the `$NVM DIR/alias` directory. This allows a name containing `..` components to escape the alias directory and access arbitrary files readable by the user, such as `../../.npmrc`. The `nvm print alias file()` function then outputs non-comment, non-empty lines from the accessed file. This can be triggered via an untrusted `.nvmrc` file when a developer executes `nvm use`, `nvm install`, or `nvm which` within a malicious repository, disclosing the first non-comment line in an error message. Additionally, using `nvm alias <traversing-name>` can disclose all non-comment lines of the target file. **Recommendations** Update to version 0.40.8 or later.