The package node-ipc version 9.2.2 is vulnerable to hidden functionality that was introduced by the maintainer. The package uses a dependency that writes a file to disk that does not pertain to the functionality of the package and is not included in versions < 9.2.2.
{
"cwe_ids": [
"CWE-912"
],
"github_reviewed": true,
"github_reviewed_at": "2022-03-16T23:54:33Z",
"nvd_published_at": null,
"severity": "LOW"
}