Executive brief
Node Version Manager (nvm), a tool used by developers to manage different versions of Node.js, is vulnerable to a path traversal flaw. If a user connects to a malicious or compromised mirror server to download Node.js, the server can force nvm to overwrite sensitive files on the user's computer, such as shell startup scripts. This could allow an attacker to gain control over the user's system the next time they open a terminal session.
Technical details
A path traversal vulnerability exists in nvm's `nvm_ls_remote_index_tab` function and other commands that refresh remote LTS aliases (e.g., `nvm install --lts`). The tool parses the `index.tab` file from a Node.js mirror and uses the 10th field (LTS codename) to create alias files under `$NVM_DIR/alias/lts` without sufficient validation. An attacker controlling a mirror or performing a Man-in-the-Middle (MitM) attack can supply a codename like `../../../.bashrc`, causing nvm to write the version string to the user's shell configuration file. This leads to arbitrary command execution when the user subsequently opens a new shell session. The issue is fixed in version 0.40.6 by validating LTS codenames and rejecting `..` path components.
Affected products
- nvm-sh nvm 0.32.1 through 0.40.5
Timeline
- 2026-07-15: advisory: GitHub Security Advisory GHSA-4ghp-wxpw-rhpg published
- 2026-07-15: patched: Version 0.40.6 released with fix