Data Exfiltration Vulnerability in Coffeescript Module
CVE-2017-16205
7.5HIGH
What is CVE-2017-16205?
The Coffeescript module contains a vulnerability that exposes sensitive user data, including private SSH keys and bash command history, to an unauthorized third-party server during its installation process, posing significant privacy risks for affected users.
Affected Version(s)
coffeescript node module 1.0.1