Skip to content

Security Alert: tmp allows arbitrary temporary file / directory write via symbolic link dir parameter #255

@akaustav

Description

@akaustav

The version of the tmp package currently used in this repository is vulnerable to the security issue described in:

And here's a sample outcome of the npm ls tmp command ran in a temporary project using v0.16.5 of apigeetool:

% npm ls tmp
project@1.0.0 /path/to/project
└─┬ apigeetool@0.16.5
  └── tmp@0.0.27

Please fix this.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions