CVE-2016-10538: CLI Project CLI
Low severity, CVSS 3.5. EPSS: 1% chance of exploitation in the next 30 days.
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
Affected products
- CLI Project CLI: before 1.0.0 (fixed in 1.0.0)
- Debian Debian Linux: version 8.0 only
Published 2018-05-31. Last modified 2026-06-17.