PatchSiren

nvm-sh CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM nvm-sh CVE published 2026-09-21

CVE-2026-94185

CVE-2026-94185 is a vulnerability in nvm that allows for the disclosure of arbitrary file contents. The vulnerability exists due to a lack of containment checks when resolving version or alias requests. An attacker can exploit this vulnerability by supplying a specially crafted version string or alias name that traverses the directory structure, allowing access to files outside the intended alias directory.