Логотип exploitDog
bind:CVE-2025-4759
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-4759

Количество 2

Количество 2

nvd логотип

CVE-2025-4759

9 месяцев назад

Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-7cfr-5cjf-32p4

9 месяцев назад

lockfile-lint-api Vulnerable to Incorrect Behavior Order

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-4759

Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.

CVSS3: 8.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-7cfr-5cjf-32p4

lockfile-lint-api Vulnerable to Incorrect Behavior Order

CVSS3: 8.3
0%
Низкий
9 месяцев назад

Уязвимостей на страницу