-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper handling of root-level ignore files in workspace contexts. npm-packlist is directly responsible for file inclusion logic, and its failure to apply root ignore rules in workspaces is a core issue. Libnpmpack's role in passing workspace/prefix context to npm-packlist (as indicated in the fix commit 'pass prefix and workspaces to libnpmpack') confirms its involvement. The patch in npm v8.11.0 addressed both components, aligning with the described vulnerability impact.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| npm | npm | >= 7.9.0, < 8.11.0 | 8.11.0 |
Ongoing coverage of React2Shell