{"id":"CVE-2022-23812","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-23812","summary":"Embedded Malicious Code in node-ipc","details":"The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address. The maintainer removed the malicious code in version 10.1.3.","published":"2022-03-16T23:54:32Z","modified":"2026-03-16T03:12:33.092894Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.0426,"percentile":0.90342,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"node-ipc","fixedVersion":"10.1.3"}],"fix":{"url":"https://github.com/RIAEvangelist/node-ipc/commit/847047cf7f81ab08352038b2204f0e7633449580","label":"RIAEvangelist/node-ipc@847047c"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23812"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/issues/233"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/issues/236"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/commit/847047cf7f81ab08352038b2204f0e7633449580"},{"type":"PACKAGE","url":"https://github.com/RIAEvangelist/node-ipc"},{"type":"WEB","url":"https://github.com/RIAEvangelist/node-ipc/blob/847047cf7f81ab08352038b2204f0e7633449580/dao/ssl-geospec.js"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220407-0005"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-NODEIPC-2426370"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-16T03:12:33.092894Z"}}