PT-2022-6672 · Npm+6 · Npm+6
Published
2022-06-02
·
Updated
2025-09-29
·
CVE-2022-29244
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
npm versions 7.9.0 through 7.13.0
npm version 7.13.0 and earlier
Description
The issue is related to the npm pack command ignoring root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag. This may have caused users to publish files into the npm registry that they did not intend to include. The problem is associated with information disclosure.
Recommendations
For npm versions 7.9.0 through 7.13.0, upgrade to the latest, patched version of npm v8.11.0 by running: npm i -g npm@latest.
For users of Node.js versions v16.15.1, v17.19.1, and v18.3.0, no additional action is required as these versions include the patched v8.11.0 version of npm.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Red Hat
Red Os
Rocky Linux
Suse
Npm