LOW 2.5 npm
GHSA-52f5-9888-hmc6 · CVE-2025-54798 tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Modified: 2/4/2026
package
pkg:npm/tmp
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Modified: 2/4/2026
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
Modified: 5/27/2026