CVE-2026-10796

nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the available versions from the mirror's index.tab and use the selected version, without sanitization, to build download URLs and shell/awk commands. Two sinks are affected by the same untrusted input: nvm_download() built a curl/wget command string and ran it with `eval`, so a version field containing command substitution (for example $(id)) was executed by the local shell; and nvm_get_checksum() interpolated the version-derived download slug into an awk program, so a crafted version could execute arbitrary commands via awk's system(). An attacker who controls the configured mirror, supplies mirror content to a user or CI on a non-default mirror, or machine-in-the-middles a non-TLS mirror can ∴ run arbitrary commands with the privileges of the user running nvm. The default mirror (https://nodejs.org over TLS) is not affected. Fixed on master (pending the next tagged release) by passing every argument as a literal argv element instead of using eval, by passing the value to awk as data via -v instead of interpolating it into the program, and by rejecting any version outside the Node.js/io.js version grammar before it is used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openjsf:node_version_manager:*:*:*:*:*:node.js:*:*

History

22 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) nvm (Node Version Manager) hasta la versión 0.40.4 ejecuta comandos arbitrarios a partir de cadenas de versión suministradas por el espejo de Node.js/io.js configurado. Comandos como 'nvm install' leen las versiones disponibles del archivo index.tab del espejo y usan la versión seleccionada, sin sanitización, para construir URLs de descarga y comandos de shell/awk. Dos sumideros se ven afectados por la misma entrada no confiable: nvm_download() construyó una cadena de comando curl/wget y la ejecutó con 'eval', por lo que un campo de versión que contenía sustitución de comandos (por ejemplo, $(id)) fue ejecutado por el shell local; y nvm_get_checksum() interpoló el 'slug' de descarga derivado de la versión en un programa awk, por lo que una versión manipulada podría ejecutar comandos arbitrarios a través de system() de awk. Un atacante que controla el espejo configurado, suministra contenido del espejo a un usuario o CI en un espejo no predeterminado, o realiza un ataque de intermediario en un espejo sin TLS, puede, por lo tanto, ejecutar comandos arbitrarios con los privilegios del usuario que ejecuta nvm. El espejo predeterminado (HTTPS://nodejs.org sobre TLS) no se ve afectado. Corregido en 'master' (pendiente de la próxima versión etiquetada) pasando cada argumento como un elemento literal de argv en lugar de usar 'eval', pasando el valor a awk como datos a través de -v en lugar de interpolarlo en el programa, y rechazando cualquier versión fuera de la gramática de versiones de Node.js/io.js antes de que sea utilizada.

04 Jun 2026, 20:33

Type Values Removed Values Added
First Time Openjsf node Version Manager
Openjsf
CPE cpe:2.3:a:openjsf:node_version_manager:*:*:*:*:*:node.js:*:*
References () https://github.com/nvm-sh/nvm/commit/6d870d182cd5333647ffa16c0d7dbcd817ec27a8 - () https://github.com/nvm-sh/nvm/commit/6d870d182cd5333647ffa16c0d7dbcd817ec27a8 - Patch
References () https://github.com/nvm-sh/nvm/commit/70fb4ede6b9731d75d86451d48caa5faffbec21c - () https://github.com/nvm-sh/nvm/commit/70fb4ede6b9731d75d86451d48caa5faffbec21c - Patch
References () https://github.com/nvm-sh/nvm/commit/90bb88748ba6c29c2cec73b18ed7057413aef308 - () https://github.com/nvm-sh/nvm/commit/90bb88748ba6c29c2cec73b18ed7057413aef308 - Patch
References () https://github.com/nvm-sh/nvm/security/advisories/GHSA-3c52-35h2-gfmm - () https://github.com/nvm-sh/nvm/security/advisories/GHSA-3c52-35h2-gfmm - Exploit, Mitigation, Patch, Vendor Advisory

04 Jun 2026, 19:16

Type Values Removed Values Added
References () https://github.com/nvm-sh/nvm/security/advisories/GHSA-3c52-35h2-gfmm - () https://github.com/nvm-sh/nvm/security/advisories/GHSA-3c52-35h2-gfmm -

04 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 18:16

Updated : 2026-07-22 20:10


NVD link : CVE-2026-10796

Mitre link : CVE-2026-10796

CVE.ORG link : CVE-2026-10796


JSON object : View

Products Affected

openjsf

  • node_version_manager
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')