{"id":"CVE-2018-7408","aliases":["GHSA-ph34-pc88-72gc"],"url":"https://o3.security/vulnerability/CVE-2018-7408","summary":"Incorrect Permission Assignment for Critical Resource in NPM","details":"An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as \"next: 5.7.0\" and therefore automatically installed by an \"npm upgrade -g npm\" command, and also announced in the vendor's blog without mention of pre-release status). It might allow local users to bypass intended filesystem access restrictions because ownerships of /etc and /usr directories are being changed unexpectedly, related to a \"correctMkdir\" issue.","published":"2018-02-22T18:29:00.253Z","modified":"2026-07-08T16:07:16.668729Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.0032,"percentile":0.24817,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"npm","fixedVersion":"5.7.1"}],"fix":{"url":"https://github.com/npm/npm/commit/74e149da6efe6ed89477faa81fef08eee7999ad0","label":"npm/npm@74e149d"},"references":[{"type":"ADVISORY","url":"http://blog.npmjs.org/post/171169301000/v571"},{"type":"ADVISORY","url":"https://github.com/npm/npm/commit/74e149da6efe6ed89477faa81fef08eee7999ad0"},{"type":"REPORT","url":"https://github.com/npm/npm/issues/19883"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7408"},{"type":"PACKAGE","url":"github.com/npm/cli"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:07:16.668729Z"}}