{"id":"GHSA-3mrp-qhcj-mwv5","summary":"Duplicate Advisory: Node CLI Allows Arbitrary File Overwrite","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-6cpc-mj5c-m9rq. This link is maintained to preserve external references.\n\n## Original Description\nAn issue exists in node-cli 0.1.0 through 0.11.3 due to predictable temporary file names in lock_file and log_file, which allows an attacker to overwrite files.","aliases":["CVE-2016-1000021"],"modified":"2026-09-10T03:49:19.627059910Z","published":"2022-05-24T17:02:32Z","withdrawn":"2023-12-08T21:57:37Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-07-28T18:34:12Z","nvd_published_at":"2019-12-03T22:15:00Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000021"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10538"},{"type":"WEB","url":"https://github.com/node-js-libs/cli/issues/81"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000021"},{"type":"WEB","url":"https://web.archive.org/web/20190430172230/https://www.npmjs.com/advisories/95"}],"affected":[{"package":{"name":"cli","ecosystem":"npm","purl":"pkg:npm/cli"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.1.0"},{"fixed":"1.0.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.11.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3mrp-qhcj-mwv5/GHSA-3mrp-qhcj-mwv5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}