Junglewise Threat Intelligence

CVE-2022-29244: npm pack root-level ignore file bypass in workspaces

CVE-2022-29244 · Severity: low · CVSS 3.1 · Published 2022-06-02

Technologies: npm (npm). Vendors: npm.

Executive brief

npm is a package manager that handles code distribution. When developers publish packages to the npm registry using workspaces (a feature for managing multiple packages in a single repository), npm incorrectly includes files that should have been excluded based on .gitignore and .npmignore rules. This could cause sensitive files, configuration data, or private information to be accidentally published to the public registry.

Technical details

The vulnerability is a file inclusion bypass (CWE-200) in npm's packing and publishing logic. When npm pack or npm publish is run with workspace flags (--workspaces or --workspace=<name>) on versions 7.9.0 to 8.10.x, root-level .gitignore and .npmignore exclusion directives are ignored, causing unintended files to be bundled into packages. The attack vector is local (requires running the affected npm command), but the impact is information disclosure through published packages in the npm registry. Patch: upgrade to npm v8.11.0 or later (included in Node.js v16.15.1, v17.19.1, and v18.3.0).

Affected products

  • npm npm >=7.9.0, <8.11.0

Timeline

  • 2022-06-02: disclosed
  • 2022-06-02: patched: npm v8.11.0 released

References

Related threats