Symlink attack due to predictable tmp folder names Affecting npm package, versions <1.3.4



    Attack Complexity High

    Threat Intelligence

    EPSS 0.04% (6th percentile)
Expand this section
4.4 medium
Expand this section
Red Hat
3.3 low

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID npm:npm:20130708
  • published 13 Feb 2017
  • disclosed 7 Jul 2013
  • credit Daniel Kahn Gillmor

How to fix?

Upgrade npm to version 1.3.3 or higher.


npm is a package manager for JavaScript. Affected versions of the package are vulnerable to Symlink attack due to predictable tmp folder names, which were named /tmp/npm-$PID. An attacker waiting for a process named npm- to load could then go to the folder and arbitrarily change the files in the tmp folder.