Arbitrary File Write in bin-links
Low severity
GitHub Reviewed
Published
Sep 4, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 4, 2020
Last updated
Jan 9, 2023
Versions of
bin-links
prior to 1.1.5 are vulnerable to an Arbitrary File Write. The package fails to restrict access to folders outside of the intendednode_modules
folder through thebin
field. This allows attackers to create arbitrary files in the system. Note it is not possible to overwrite files that already exist.Recommendation
Upgrade to version 1.1.5 or later.
References