VDB
Sign up
CRITICAL9.8

GHSA-97m3-w2cp-4xx6

Embedded Malicious Code in node-ipc

Quick fix

GHSA-97m3-w2cp-4xx6 — node-ipc: upgrade to the fixed version with the command below.

npm install node-ipc@10.1.3

Details

The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address. The maintainer removed the malicious code in version 10.1.3.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-ipc
Introduced in: 10.1.1Fixed in: 10.1.3
Fixnpm install node-ipc@10.1.3

References