← العودة للجدول
CVE-2026-44705
CVE-2026-44705 — tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the t
📅 2026-06-11
🟠 High 🔥 No NVD Exploit Supply Chain

📋 الوصف الكامل

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the config

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-44705

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-44705 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←