GHSA-gqf6-75v8-vr26

Suggest an improvement
Source
https://github.com/advisories/GHSA-gqf6-75v8-vr26
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-gqf6-75v8-vr26/GHSA-gqf6-75v8-vr26.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gqf6-75v8-vr26
Published
2020-09-04T16:56:11Z
Modified
2020-08-31T18:58:56Z
Summary
Arbitrary File Write in bin-links
Details

Versions of bin-links prior to 1.1.5 are vulnerable to an Arbitrary File Write. The package fails to restrict access to folders outside of the intended node_modules folder through the bin field. This allows attackers to create arbitrary files in the system. Note it is not possible to overwrite files that already exist.

Recommendation

Upgrade to version 1.1.5 or later.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:58:56Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / bin-links

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-gqf6-75v8-vr26/GHSA-gqf6-75v8-vr26.json"