We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.
Reserved 2025-07-29 | Published 2025-08-07 | Updated 2025-08-07 | Assigner GitHub_MCWE-59: Improper Link Resolution Before File Access ('Link Following')
github.com/...de-tmp/security/advisories/GHSA-52f5-9888-hmc6
github.com/raszi/node-tmp/issues/207
github.com/...ommit/188b25e529496e37adaf1a1d9dccb40019a08b1b
Support options