Skip to content

chore(deps): update npm to v11.9.0 [security]#372

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-npm-vulnerability
Open

chore(deps): update npm to v11.9.0 [security]#372
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-npm-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 4, 2026

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change OpenSSF
npm (source) packageManager minor 11.4.211.9.0 OpenSSF Scorecard

npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVE-2026-0775 / GHSA-3966-f6p6-2qr9

More information

Details

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user.

Severity

  • CVSS Score: 7.0 / 10 (High)
  • Vector String: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

npm/cli (npm)

v11.9.0

Compare Source

Features
Bug Fixes
Dependencies
Chores

v11.8.0

Compare Source

Features
  • 545e861 #​8828 show proxy environment variables in npm config list (Max Black)
Bug Fixes
Documentation
Dependencies
Chores

v11.7.0

Compare Source

Features
Bug Fixes
Documentation
Chores
Dependencies

v11.6.4

Compare Source

Documentation
Dependencies

v11.6.3

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

v11.6.2

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

v11.6.1

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the t:security label Feb 4, 2026
@renovate renovate bot requested a review from Djaytan as a code owner February 4, 2026 20:35
@sonarqubecloud
Copy link

sonarqubecloud bot commented Feb 4, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants