CVE-2026-94185

CVE-2026-94185 published: nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no containment check, so a name containing a `..` component ...

View full NVD advisory → ← Back to CVE watch