GHSA-97m3-w2cp-4xx6
CRITICALCVE-2022-23812The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address. The maintainer removed the malicious code in version 10.1.3.
- Affected
- >= 10.1.1, < 10.1.3
- Fixed in
- 10.1.3
- Weakness
- CWE-94
- Published
- 2022-03-16
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference