Skip to content

Comments

fix(deps): update dependency npm to v11.9.0 [security]#388

Merged
renovate-sh-app[bot] merged 1 commit intomainfrom
renovate/npm-npm-vulnerability
Feb 5, 2026
Merged

fix(deps): update dependency npm to v11.9.0 [security]#388
renovate-sh-app[bot] merged 1 commit intomainfrom
renovate/npm-npm-vulnerability

Conversation

@renovate-sh-app
Copy link
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
npm (source) 11.4.211.9.0 age confidence

npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVE-2026-0775 / GHSA-3966-f6p6-2qr9

More information

Details

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user.

Severity

  • CVSS Score: 7.0 / 10 (High)
  • Vector String: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

npm/cli (npm)

v11.9.0

Compare Source

Features
Bug Fixes
Dependencies
Chores

v11.8.0

Compare Source

Features
  • 545e861 #​8828 show proxy environment variables in npm config list (Max Black)
Bug Fixes
Documentation
Dependencies
Chores

v11.7.0

Compare Source

Features
Bug Fixes
Documentation
Chores
Dependencies

v11.6.4

Compare Source

Documentation
Dependencies

v11.6.3

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

v11.6.2

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

v11.6.1

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

| datasource | package | from   | to     |
| ---------- | ------- | ------ | ------ |
| npm        | npm     | 11.4.2 | 11.9.0 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app renovate-sh-app bot merged commit bf33e44 into main Feb 5, 2026
15 checks passed
@renovate-sh-app renovate-sh-app bot deleted the renovate/npm-npm-vulnerability branch February 5, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant