A vulnerability that allowed an update to be released for any package in the NPM repository.
GitHub has disclosed information about two incidents within the NPM package repository infrastructure. On November 2, external security researchers (Kajetan Grzybowski and Maciej Piechota) reported a vulnerability in the NPM repository as part of the Bug Bounty program. This vulnerability allowed the publication of a new version of any package using an unauthorized account without the necessary permissions to perform such updates. The vulnerability was caused by […]
