Executive brief
@npmcli/arborist is a library used by npm to manage package installation and the node_modules folder structure. If an attacker can replace the node_modules directory with a symbolic link, arborist will write package contents to arbitrary locations on the file system, potentially leading to arbitrary code execution. This could be exploited by tricking developers into running npm install on a malicious repository.
Technical details
The vulnerability is a symlink following issue (CWE-61, CWE-59) in @npmcli/arborist, the npm package dependency tree calculator and node_modules manager. When arborist extracts package contents into node_modules, it does not verify that node_modules is a real directory rather than a symbolic link; if node_modules is a symlink, arborist will follow it and write packages to an arbitrary filesystem location. An attacker can exploit this by supplying a malicious git repository and tricking a developer into running npm install, or by using a preinstall script to replace node_modules with a symlink. The attack requires local access and user interaction (developer running npm install), but achieves arbitrary file creation, overwrite, and potential code execution. Fixed in version 2.8.2 (included in npm v7.20.7+); the fix validates that node_modules is a real directory before extracting packages.
Affected products
- npm @npmcli/arborist <2.8.2
Timeline
- 2021-08-31: disclosed: GHSA-gmw6-94gg-2rc2 published
- 2021-08-31: patched: Version 2.8.2 released; included in npm v7.20.7+