CVE-2013-4116

EPSS 0.10%

Local Privilege Escalation in npm

Published: 9/1/2020Modified: 2/4/2026
Also known as:GHSA-v3jv-wrf4-5845CGA-jv7c-gh6x-xcqhDEBIAN-CVE-2013-4116

Description

Affected versions of `npm` use predictable temporary file names during archive unpacking. If an attacker can create a symbolic link at the location of one of these temporary file names, the attacker can arbitrarily write to any file that the user which owns the `npm` process has permission to write to, potentially resulting in local privilege escalation. ## Recommendation Update to version 1.3.3 or later.

Affected packages (2)

References (12)