Executive brief
npm is a package manager that handles code distribution. When developers publish packages to the npm registry using workspaces (a feature for managing multiple packages in a single repository), npm incorrectly includes files that should have been excluded based on .gitignore and .npmignore rules. This could cause sensitive files, configuration data, or private information to be accidentally published to the public registry.
Technical details
The vulnerability is a file inclusion bypass (CWE-200) in npm's packing and publishing logic. When npm pack or npm publish is run with workspace flags (--workspaces or --workspace=<name>) on versions 7.9.0 to 8.10.x, root-level .gitignore and .npmignore exclusion directives are ignored, causing unintended files to be bundled into packages. The attack vector is local (requires running the affected npm command), but the impact is information disclosure through published packages in the npm registry. Patch: upgrade to npm v8.11.0 or later (included in Node.js v16.15.1, v17.19.1, and v18.3.0).
Affected products
- npm npm >=7.9.0, <8.11.0
Timeline
- 2022-06-02: disclosed
- 2022-06-02: patched: npm v8.11.0 released