Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31890
HistorySep 01, 2021 - 3:51 a.m.

Remote Code Execution (RCE)

2021-09-0103:51:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

28.8%

@npmcli/arborist is vulnerable to remote code execution. The vulnerability exists due to a symlink dependency where an attacker is able to create arbitrary contents to be written to any location on the filesystem.