GHSA-3966-f6p6-2qr9

Suggest an improvement
Source
https://github.com/advisories/GHSA-3966-f6p6-2qr9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-3966-f6p6-2qr9/GHSA-3966-f6p6-2qr9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3966-f6p6-2qr9
Aliases
  • CVE-2026-0775
Downstream
CGA (52)
MINI (1)
Withdrawn
2026-02-06T22:28:42Z
Published
2026-01-23T06:31:24Z
Modified
2026-09-10T03:50:32Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Details

Duplicate Advisory

This advisory has been withdrawn because describes a dependency bump and therefore, per CVE CNA rule 4.1.12, is a duplicate of GHSA-34x7-hfp2-rc4v/CVE-2026-24842. Additionally, per https://github.com/npm/cli/issues/8939#issuecomment-3862719883, npm cli should not be listed as an affected product. This link is maintained to preserve external references.

Original Description

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user.

Database specific
{
    "cwe_ids":  [
        "CWE-732"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-03T17:42:06Z",
    "nvd_published_at":  "2026-01-23T04:16:04Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / npm

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
11.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-3966-f6p6-2qr9/GHSA-3966-f6p6-2qr9.json"