Known vulnerabilities in node-tmp
Vendor:
raszi
Software:
node-tmp
Software CPE:
cpe:2.3:a:raszi:node-tmp:*:*:*:*:*:*:*:*
Website:
https://github.com/raszi
Total vulnerabilities:
2
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132348 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-44705 |
CWE-22 | High | 0.2.6 | 27.05.2026 |
SB2026052717 SB2026072621 SB2026072624 |
||
| #VU118198 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-54798 |
CWE-59 | Low | 0.2.4 | 07.11.2025 |
SB2025110743 SB2025110755 SB2025112543 and 9 more |