CVE-2017-16074
Résumé
In late July/August 2017, a user named 'hacktask' published around 37 typosquatting packages on npm with names mimicking popular libraries, the most notable being 'crossenv' (impersonating cross-env). The package replicated the legitimate functionality but added an install-time snippet that harvested all environment variables, often containing tokens, keys and credentials, and exfiltrated them to npm.hacktask.net. crossenv was tracked as CVE-2017-16074; actual installs were limited (estimated under ~50) and npm removed roughly 40 packages.
Références
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-75912
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
- HIGHCVE-2026-75915
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
- HIGHCVE-2026-75859
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
- HIGHCVE-2026-72804
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
- MEDIUMCVE-2026-61842
Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)
- MEDIUMCVE-2026-73229
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests