Description
NPM package next-npm-version1.0.1 is vulnerable to Command injection.
Published: 2026-05-07
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic command injection flaw that allows an attacker to execute arbitrary system commands. Consequently, an adversary could gain unauthorized access to the host, modify or delete files, and potentially disrupt services, thereby compromising confidentiality, integrity, and availability.

Affected Systems

The affected component is the npm package next-npm-version version 1.0.1, which is distributed via npm. It is typically used in Node.js environments and may be incorporated into build or deployment scripts.

Risk and Exploitability

No published CVSS or EPSS score is available, but command injection is generally considered a high‑severity weakness. The likely attack vector is indirect—through a user’s input that is passed unchecked to a shell command invoked by the package. If the package processes data from untrusted sources, an attacker could exploit the flaw to run arbitrary code.

Generated by OpenCVE AI on May 7, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade next-npm-version to a patched or later release if one is available.
  • If an update is not yet provided, remove the package from the project or place it in a strictly isolated environment with limited privileges.
  • Where the package must remain, enforce strict input validation or replace the vulnerable functionality with a safer alternative that does not invoke the shell.

Generated by OpenCVE AI on May 7, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Afeiship
Afeiship next-npm-version
Vendors & Products Afeiship
Afeiship next-npm-version

Thu, 07 May 2026 15:30:00 +0000

Type Values Removed Values Added
Title Command Injection in next-npm-version 1.0.1
Weaknesses CWE-78

Thu, 07 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description NPM package next-npm-version1.0.1 is vulnerable to Command injection.
References

Subscriptions

Afeiship Next-npm-version
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-07T14:22:46.851Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-07T15:16:04.820

Modified: 2026-05-07T15:51:01.053

Link: CVE-2025-63706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T21:25:18Z

Weaknesses