Junglewise Threat Intelligence

CVE-2016-10675: libsbmlsim insecure HTTP resource download

CVE-2016-10675 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm.

Executive brief

libsbmlsim is a scientific simulation library that downloads executable components over unencrypted HTTP connections. An attacker positioned on the network path can intercept and replace the downloaded executable with malicious code, gaining complete control over systems running the library. This vulnerability allows remote code execution without any user interaction.

Technical details

The vulnerability is a missing encryption of sensitive data (CWE-311) where libsbmlsim downloads executable resources over unencrypted HTTP instead of HTTPS. An attacker with a privileged network position (man-in-the-middle capability) can intercept the HTTP response and inject a malicious executable, leading to arbitrary code execution on the target system. No authentication or user interaction is required for exploitation. The attack surface is particularly broad on public networks, though private networks remain vulnerable to compromised network infrastructure or ISP-level attackers. No patch has been released; the advisory recommends avoiding the package entirely or restricting its use to isolated, controlled environments.

Affected products

  • npm libsbmlsim ≤ 0.0.2

Timeline

  • 2019-02-18: disclosed