PT-2026-96035 · Nvm · Nvm

·

CVE-2026-94185

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

6.7

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions nvm versions prior to 0.40.8
Description The nvm alias() function fails to perform a containment check when concatenating a requested version or alias name to the $NVM DIR/alias directory. This allows a name containing .. components to escape the alias directory and access arbitrary files readable by the user, such as ../../.npmrc. The nvm print alias file() function then outputs non-comment, non-empty lines from the accessed file. This can be triggered via an untrusted .nvmrc file when a developer executes nvm use, nvm install, or nvm which within a malicious repository, disclosing the first non-comment line in an error message. Additionally, using nvm alias <traversing-name> can disclose all non-comment lines of the target file.
Recommendations Update to version 0.40.8 or later.

Exploit

Fix

Path traversal

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94185
GHSA-8GRH-Q73J-FFRC

Affected Products

Nvm