{"id":"GHSA-w87r-vg9q-crqm","summary":"zx Uses Incorrectly-Resolved Name or Reference","details":"When zx is invoked with --prefer-local=\u003cpath\u003e, the CLI creates a symlink named ./node_modules pointing to \u003cpath\u003e/node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external \u003cpath\u003e/node_modules outside the current working directory.","aliases":["CVE-2025-13437"],"modified":"2025-11-21T18:44:00.001863Z","published":"2025-11-20T18:31:01Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-11-21T18:01:32Z","nvd_published_at":"2025-11-20T17:15:49Z","cwe_ids":["CWE-706"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13437"},{"type":"WEB","url":"https://github.com/google/zx/issues/1348"},{"type":"WEB","url":"https://github.com/google/zx/pull/1349"},{"type":"WEB","url":"https://github.com/google/zx/pull/1355"},{"type":"WEB","url":"https://github.com/google/zx/commit/9ef6d3c9962c4ba01e3fb8075855570c192b4681"},{"type":"WEB","url":"https://github.com/google/zx/commit/a4d1bc2467f305f1c91d62506e215f307dc1fbeb"},{"type":"PACKAGE","url":"https://github.com/google/zx"}],"affected":[{"package":{"name":"zx","ecosystem":"npm","purl":"pkg:npm/zx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.8.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-w87r-vg9q-crqm/GHSA-w87r-vg9q-crqm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U"}]}