CVE detail
CVE-2013-4116 — CVE-2013-4116
Published 2014-04-22 · Modified 2026-06-16 · Vendor node_packaged_modules_project · Product node_packaged_modules · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0037
EPSS probability
exploitation probability, 30d
30.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References