{"id":"CVE-2026-94185","published":"2026-09-21T03:16:34.243","lastModified":"2026-09-21T20:17:41.257","description":"nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no containment check, so a name containing a `..` component escaped the alias directory; under the default layout an alias such as `../../.npmrc` resolves to a file in the user's home directory. nvm_print_alias_file() then emits every non-comment, non-empty line of whatever was opened. A version string taken from an untrusted .nvmrc reaches this path, so a developer who runs `nvm use`, `nvm install`, or `nvm which` inside an attacker-supplied repository discloses the first non-comment line of an arbitrary file readable by that user, in the resulting \"is not yet installed\" error message. A user-supplied `nvm alias <traversing-name>` discloses every non-comment line of the target file. There is no integrity or availability impact, and no command execution on this path.","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cwes":["CWE-22","CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://github.com/nvm-sh/nvm/security/advisories/GHSA-8grh-q73j-ffrc","tags":[]}],"exploitRefs":[{"url":"https://github.com/nvm-sh/nvm/security/advisories/GHSA-8grh-q73j-ffrc","tags":[]}],"hasPoc":true,"ai":null}