Local Privilege Escalation in npm
        
  Low severity
        
          GitHub Reviewed
      
        Published
          Sep 1, 2020 
          to the GitHub Advisory Database
          •
          Updated Jan 9, 2023 
      
  
Description
        Reviewed
      Aug 31, 2020 
    
  
        Published to the GitHub Advisory Database
      Sep 1, 2020 
    
  
        Last updated
      Jan 9, 2023 
    
  
Affected versions of
npmuse predictable temporary file names during archive unpacking. If an attacker can create a symbolic link at the location of one of these temporary file names, the attacker can arbitrarily write to any file that the user which owns thenpmprocess has permission to write to, potentially resulting in local privilege escalation.Recommendation
Update to version 1.3.3 or later.
References