Skip to content

chore(deps): update dependency npm to v11.9.0 [security] (foreman-3.18)#977

Open
red-hat-konflux[bot] wants to merge 1 commit intoforeman-3.18from
konflux/mintmaker/foreman-3.18-foreman-3.18/npm-npm-vulnerability
Open

chore(deps): update dependency npm to v11.9.0 [security] (foreman-3.18)#977
red-hat-konflux[bot] wants to merge 1 commit intoforeman-3.18from
konflux/mintmaker/foreman-3.18-foreman-3.18/npm-npm-vulnerability

Conversation

@red-hat-konflux
Copy link
Contributor

@red-hat-konflux red-hat-konflux bot commented Feb 4, 2026

Note: This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
npm (source) 11.4.2 -> 11.9.0 age confidence

npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVE-2026-0775 / GHSA-3966-f6p6-2qr9

More information

Details

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user.

Severity

  • CVSS Score: 7.0 / 10 (High)
  • Vector String: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

npm/cli (npm)

v11.9.0

Compare Source

Features
Bug Fixes
Dependencies
Chores

v11.8.0

Compare Source

Features
  • 545e861 #​8828 show proxy environment variables in npm config list (Max Black)
Bug Fixes
Documentation
Dependencies
Chores

v11.7.0

Compare Source

Features
Bug Fixes
Documentation
Chores
Dependencies

v11.6.4

Compare Source

Documentation
Dependencies

v11.6.3

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

v11.6.2

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

v11.6.1

Compare Source

Bug Fixes
Documentation
Dependencies
Chores

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot requested a review from rexwhite as a code owner February 4, 2026 20:58
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/foreman-3.18-foreman-3.18/npm-npm-vulnerability branch from 636f297 to 835f0be Compare February 4, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants