Local Privilege Escalation Vulnerability in npm CLI by npm Inc.
CVE-2026-0775
7HIGH
What is CVE-2026-0775?
A local privilege escalation vulnerability has been identified in npm CLI, specifically concerning the handling of modules from unsecured locations. An attacker with the ability to execute low-privileged code on the system can exploit this flaw to escalate their privileges and execute arbitrary code within the context of a target user. Mitigation strategies should be implemented promptly to secure affected installations.
Affected Version(s)
cli 10.9.0
