PT-2026-96035 · Nvm · Nvm
CVSS v4.0
6.7
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
nvm versions prior to 0.40.8
Description
The
nvm alias() function fails to perform a containment check when concatenating a requested version or alias name to the $NVM DIR/alias directory. This allows a name containing .. components to escape the alias directory and access arbitrary files readable by the user, such as ../../.npmrc. The nvm print alias file() function then outputs non-comment, non-empty lines from the accessed file. This can be triggered via an untrusted .nvmrc file when a developer executes nvm use, nvm install, or nvm which within a malicious repository, disclosing the first non-comment line in an error message. Additionally, using nvm alias <traversing-name> can disclose all non-comment lines of the target file.Recommendations
Update to version 0.40.8 or later.
Exploit
Fix
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nvm