1 results (0.015 seconds)

CVSS: 5.4EPSS: %CPEs: 1EXPL: 0

29 Jan 2026 — A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() function uses eval to execute wget commands, and the NVM_AUTH_HEADER environment variable was not sanitized in the wget code path (though it was sanitized in the curl code path). An attacker who can set environment variables in a victim's shell environment (e.g., via malicious CI/CD configurations, compromised dotfiles, or Docker images) can inject arbitrary shell commands that execute when t... • https://github.com/nvm-sh/nvm • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') •