{"id":"GHSA-97m3-w2cp-4xx6","summary":"Embedded Malicious Code in node-ipc","details":"The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address. The maintainer removed the malicious code in version 10.1.3.","aliases":["CVE-2022-23812"],"modified":"2026-03-16T03:12:33.092894Z","published":"2022-03-16T23:54:32Z","database_specific":{"github_reviewed_at":"2022-03-16T23:54:32Z","nvd_published_at":"2022-03-16T16:15:00Z","cwe_ids":["CWE-506","CWE-94"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23812"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/issues/233"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/issues/236"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/commit/847047cf7f81ab08352038b2204f0e7633449580"},{"type":"PACKAGE","url":"https://github.com/RIAEvangelist/node-ipc"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/blob/847047cf7f81ab08352038b2204f0e7633449580/dao/ssl-geospec.js"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220407-0005"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-NODEIPC-2426370"}],"affected":[{"package":{"name":"node-ipc","ecosystem":"npm","purl":"pkg:npm/node-ipc"},"ranges":[{"type":"SEMVER","events":[{"introduced":"10.1.1"},{"fixed":"10.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-97m3-w2cp-4xx6/GHSA-97m3-w2cp-4xx6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}