{"id":"CVE-2026-1665","summary":"Command Injection in nvm via NVM_AUTH_HEADER in wget code path","details":"A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() function uses eval to execute wget commands, and the NVM_AUTH_HEADER environment variable was not sanitized in the wget code path (though it was sanitized in the curl code path). An attacker who can set environment variables in a victim's shell environment (e.g., via malicious CI/CD configurations, compromised dotfiles, or Docker images) can inject arbitrary shell commands that execute when the victim runs nvm commands that trigger downloads, such as 'nvm install' or 'nvm ls-remote'.","modified":"2026-08-12T03:51:37.984342548Z","published":"2026-01-29T23:04:05.741Z","database_specific":{"cna_assigner":"openjs","cwe_ids":["CWE-78","CWE-95"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1665.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1665.json"},{"type":"ADVISORY","url":"https://github.com/nvm-sh/nvm/releases/tag/v0.40.4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1665"},{"type":"FIX","url":"https://github.com/nvm-sh/nvm/commit/44e2590cdf257faf7d885e4470be8dc66cec9506"},{"type":"FIX","url":"https://github.com/nvm-sh/nvm/pull/3380"},{"type":"PACKAGE","url":"https://github.com/nvm-sh/nvm"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nvm-sh/nvm","events":[{"introduced":"deac4e0932eb3031656cdcbe12f0a7be2cacb69f"},{"fixed":"44e2590cdf257faf7d885e4470be8dc66cec9506"},{"fixed":"62387b8f92aa012d48202747fd75c40850e5e261"}],"database_specific":{"extracted_events":[{"introduced":"0.40.0"},{"last_affected":"0.40.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v0.40.3","v0.40.2","v0.40.1","v0.40.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1665.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}