PT-2022-6672 · Npm+6 · Npm+6

Published

2022-06-02

·

Updated

2025-09-29

·

CVE-2022-29244

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions npm versions 7.9.0 through 7.13.0 npm version 7.13.0 and earlier
Description The issue is related to the npm pack command ignoring root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag. This may have caused users to publish files into the npm registry that they did not intend to include. The problem is associated with information disclosure.
Recommendations For npm versions 7.9.0 through 7.13.0, upgrade to the latest, patched version of npm v8.11.0 by running: npm i -g npm@latest. For users of Node.js versions v16.15.1, v17.19.1, and v18.3.0, no additional action is required as these versions include the patched v8.11.0 version of npm.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6595
ALSA-2022_6595
ALSA-2025_16880
ALT-PU-2022-2225
BDU:2023-03309
CVE-2022-29244
GHSA-HJ9C-8JMM-8C52
OPENSUSE-SU-2022_3250-1
OPENSUSE-SU-2022_3251-1
OPENSUSE-SU-2024:12280-1
RHSA-2022:6595
RHSA-2022_6595
RLSA-2022:6595
SUSE-SU-2022:3196-1
SUSE-SU-2022:3250-1
SUSE-SU-2022:3251-1
SUSE-SU-2022_3196-1
SUSE-SU-2022_3250-1
SUSE-SU-2022_3251-1

Affected Products

Alt Linux
Almalinux
Red Hat
Red Os
Rocky Linux
Suse
Npm