Global executable ownership check accepts a prefix-colliding package directory
Fixed in: bin-links 6.0.1; also verified in npm 11.15.0 (bin-links 6.0.2)
details
- Finding IDs
- F-NPM-CLI-001
- Status
- fixed publicly
- Fixed in
- bin-links 6.0.1; also verified in npm 11.15.0 (bin-links 6.0.2)
- Note
- When a user installs a package globally, bin-links decides whether an existing executable belongs to that package. A startsWith comparison also accepted sibling directories whose names share the same prefix, permitting an unrelated executable link or shim to be replaced without force. PR #173, merged 13 May 2026, requires an exact directory match or a prefix followed by the platform path separator in check-bin, link-gently and shim-bin, with regression tests. The boundary check is present in bin-links 6.0.1 and the bin-links 6.0.2 bundled with npm 11.15.0. This concerns package installation and executable ownership, not execution without a user installing a package. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.
F-NPM-CLI-001: Access control. A textual path prefix is mistaken for package ownership, allowing replacement of another package's executable link. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-NPM-CLI-001
Security area (1seal assessment): Authorization. A textual path prefix is mistaken for package ownership, allowing replacement of another package's executable link. Reviewed 26 Sep 2026.