vercel Vulnerabilities and Affected Products
Vulnerabilities associated with pkg.
Products
Clear product- next.js48 vulnerabilities
- ai3 vulnerabilities
- turborepo3 vulnerabilities
- ms2 vulnerabilities
- next2 vulnerabilities
- @ai-sdk/harness-codex1 vulnerability
- @ai-sdk/harness-opencode1 vulnerability
- AI SDK1 vulnerability
- flags1 vulnerability
- hyper1 vulnerability
- Nuxt Devtools1 vulnerability
- pkg1 vulnerability
- vercel1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-24828MEDIUM | Local Privilege Escalation in execuatables bundled by pkgpkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On unix systems, this is `/tmp/pkg/*` which is a shared directory for all users on the same local system. There is no uniqueness to the package names within this directory, they are predictable. An attacker who has access to the same local system has the ability to replace the genuine executables in the shared directory with malicious executables of the… CWE-276Feb 9, 2024 | CVSS6.6v3.1 | EPSS0.231% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |