npm package report

Is github.com/opencontainers/runc safe?

2 known vulnerabilities.

cvss
not scored

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-fh74-hm69-rqjw, the advisory selected below

// advisories

GHSA-fh74-hm69-rqjw

UNKNOWNCVE-2019-19921

By crafting a malicious root filesystem (with /proc being a symlink to a directory which was inside a volume shared with another running container), an attacker in control of both containers can trick runc into not correctly configuring the container's security labels and not correctly masking paths inside /proc which contain potentially-sensitive information about the host (or even allow for dire

Affected
>=0, <1.0.0-rc9.0.20200122160610-2fc03cc11c77
Fixed in
1.0.0-rc9.0.20200122160610-2fc03cc11c77
Published
2021-05-27
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:40 UTC. The most recent advisory here was published 2021-05-27. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/opencontainers/runc safe? npm package security report | CyberXYZ