{"id":"GHSA-v45m-2wcp-gg98","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v45m-2wcp-gg98","summary":"Global node_modules Binary Overwrite in bin-links","details":"Versions of  `bin-links` prior to 1.1.6 are vulnerable to a Global node_modules Binary Overwrite. It fails to prevent globally-installed binaries to be overwritten by other package installs. For example, if a package was installed globally and created a `serve` binary, any subsequent installs of packages that also create a `serve` binary would overwrite the first binary. This behavior is still allowed in local installations.\n\n\n## Recommendation\n\nUpgrade to version 1.1.6 or later.","published":"2020-09-04T17:18:44Z","modified":"2020-08-31T18:59:19Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"bin-links","fixedVersion":"1.1.6"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1438"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:59:19Z"}}