Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31888
HistorySep 01, 2021 - 2:58 a.m.

Remote Code Execution (RCE)

2021-09-0102:58:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.001 Low

EPSS

Percentile

28.8%

@npmcli/arborist is vulnerable to Remote Code Execution (RCE). The vulnerability exists due to the lack of sanitization of the symlink and the assigned dependency in the root level.