CVE-2025-4759
Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:P
- EPSS probability
- 0.42%
- CWE
- CWE-179
- Published
- 2025-05-16
- Last modified
- 2026-03-13
Affected products
- n/a lockfile-lint-api
Weakness type
Related vulnerabilities
- CVE-2026-49414 — ASLR bypass for setuid executables via procctl(2)
- CVE-2026-3832 — Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
- CVE-2024-41686 — Password Policy Bypass Vulnerability
- CVE-2022-1271 — An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied...