{"id":"GHSA-8gr3-2gjw-jj7g","summary":"Hidden functionality in node-ipc","details":"The package node-ipc version 9.2.2 is vulnerable to hidden functionality that was introduced by the maintainer. The package uses a dependency that writes a file to disk that does not pertain to the functionality of the package and is not included in versions \u003c 9.2.2.","modified":"2022-03-16T23:54:33Z","published":"2022-03-16T23:54:33Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2022-03-16T23:54:33Z","nvd_published_at":null,"cwe_ids":["CWE-912"]},"references":[{"type":"PACKAGE","url":"https://github.com/RIAEvangelist/node-ipc"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/releases/tag/9.2.2"}],"affected":[{"package":{"name":"node-ipc","ecosystem":"npm","purl":"pkg:npm/node-ipc"},"versions":["9.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-8gr3-2gjw-jj7g/GHSA-8gr3-2gjw-jj7g.json"}}],"schema_version":"1.9.0"}