{"id":"GHSA-v45m-2wcp-gg98","summary":"Global node_modules Binary Overwrite in bin-links","details":"Versions of  `bin-links` prior to 1.1.6 are vulnerable to a Global node_modules Binary Overwrite. It fails to prevent globally-installed binaries to be overwritten by other package installs. For example, if a package was installed globally and created a `serve` binary, any subsequent installs of packages that also create a `serve` binary would overwrite the first binary. This behavior is still allowed in local installations.\n\n\n## Recommendation\n\nUpgrade to version 1.1.6 or later.","modified":"2020-08-31T18:59:19Z","published":"2020-09-04T17:18:44Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:59:19Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1438"}],"affected":[{"package":{"name":"bin-links","ecosystem":"npm","purl":"pkg:npm/bin-links"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-v45m-2wcp-gg98/GHSA-v45m-2wcp-gg98.json"}}],"schema_version":"1.9.0"}