« List of all CVEs

CVE-2016-10538

Published: 5/31/2018 Last updated: 9/17/2024 Reserved: 10/29/2017

The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.

CNA assigner: hackerone (36234546-b8fa-4601-9d6f-f4e334aa8ea1) Requested by: n/a

Opam packages affected (1)

conf-npm

Products affected (1)

Product Vendor Version
cli node module HackerOne WCD9380

References (6)