CVE-2026-0775: Npm CLI

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25430.

Affected products

  • Npm CLI: version 10.9.0 only
  • Red Hat Confidential Compute Attestation
  • Red Hat Cryostat 4
  • Red Hat Logging Subsystem For Red Hat Openshift
  • Red Hat Migration Toolkit For Containers
  • Red Hat Multicluster Engine For Kubernetes
  • Red Hat Network Observability Operator
  • Red Hat Node Healthcheck Operator
  • Red Hat Openshift Lightspeed
  • Red Hat Openshift Pipelines
  • Red Hat Openshift Serverless
  • Red Hat Red Hat 3scale API Management Platform 2
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2
  • Red Hat Red Hat Amq Broker 7
  • Red Hat Red Hat Ansible Automation Platform 2
  • Red Hat Red Hat Build Of Apache Camel - Hawtio 4
  • Red Hat Red Hat Connectivity Link 1
  • Red Hat Red Hat Developer Hub
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
  • Red Hat Red Hat Fuse 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • and 10 more

Published 2026-01-23. Last modified 2026-07-15.