The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address. The maintainer removed the malicious code in version 10.1.3.
{
"github_reviewed": true,
"severity": "CRITICAL",
"github_reviewed_at": "2022-03-16T23:54:32Z",
"nvd_published_at": "2022-03-16T16:15:00Z",
"cwe_ids": [
"CWE-506",
"CWE-94"
]
}