Showing 1 vulnerability on this page for pkg

Signals CISA KEV Ransomware Nuclei
vercel vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Local Privilege Escalation in execuatables bundled by pkg

pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On unix systems, this is `/tmp/pkg/*` which is a shared directory for all users on the same local system. There is no uniqueness to the package names within this directory, they are predictable. An attacker who has access to the same local system has the ability to replace the genuine executables in the shared directory with malicious executables of the

CWE-276Feb 9, 2024
CVSS6.6v3.1EPSS0.231%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX