No advisories yet.
Solution
Upgrade to nvm 0.40.8 or later, which rejects any `..` path component in nvm_alias() and nvm_version_path().
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvm-sh
Nvm-sh nvm |
|
| Vendors & Products |
Nvm-sh
Nvm-sh nvm |
Mon, 21 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no containment check, so a name containing a `..` component escaped the alias directory; under the default layout an alias such as `../../.npmrc` resolves to a file in the user's home directory. nvm_print_alias_file() then emits every non-comment, non-empty line of whatever was opened. A version string taken from an untrusted .nvmrc reaches this path, so a developer who runs `nvm use`, `nvm install`, or `nvm which` inside an attacker-supplied repository discloses the first non-comment line of an arbitrary file readable by that user, in the resulting "is not yet installed" error message. A user-supplied `nvm alias <traversing-name>` discloses every non-comment line of the target file. There is no integrity or availability impact, and no command execution on this path. | |
| Title | nvm alias resolution follows `..` and discloses files outside $NVM_DIR/alias | |
| Weaknesses | CWE-200 CWE-22 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: harborist
Published:
Updated: 2026-09-21T02:27:00.752Z
Reserved: 2026-09-21T02:14:56.481Z
Link: CVE-2026-94185
No data.
Status : Received
Published: 2026-09-21T03:16:34.243
Modified: 2026-09-21T03:16:34.243
Link: CVE-2026-94185
No data.
OpenCVE Enrichment
Updated: 2026-09-21T04:30:08Z