GHSA-93f3-23rq-pjfp
GitHub Security Advisory
npm CLI exposing sensitive information through logs
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like `<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>`. The password value is not redacted and is printed to stdout and also to any generated log files.
Affected Packages
npm
npm
Affected versions:
0
(fixed in 6.14.6)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.