
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0775 is a local privilege escalation vulnerability in npm CLI, classified as an "Uncontrolled Search Path Element" flaw (also described as Incorrect Permission Assignment for Critical Resource, CWE-732). It allows local attackers with low-privileged code execution to escalate privileges and execute arbitrary code in the context of a target user by exploiting insecure module loading. The vulnerability was reported to npm on November 13, 2024; the vendor deemed it "by design" and declined to patch it, leading ZDI to publish a 0-day advisory on January 12, 2026. The CVSS v3 base score is 7.0–7.8 HIGH (ZDI assigned 7.8 with AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) (ZDI Advisory).
The root cause is CWE-732 (Incorrect Permission Assignment for Critical Resource), specifically an uncontrolled search path element in npm CLI's module resolution logic. When npm CLI loads modules, it references an unsecured or attacker-writable directory location, allowing a low-privileged attacker to plant a malicious module that gets loaded in place of the legitimate one. This is a DLL/module hijacking-style attack applicable on Windows systems where npm resolves modules from paths that can be influenced by unprivileged users. The vendor acknowledged the report but classified the behavior as intentional design, and no patch has been issued; ZDI published the advisory (ZDI-CAN-25430) as a 0-day after exhausting coordinated disclosure efforts (ZDI Advisory, ZDI Blog).
Successful exploitation grants the attacker full confidentiality, integrity, and availability impact on the affected system, as they can execute arbitrary code in the context of the target user running npm CLI. This could enable credential theft, installation of persistent malware, lateral movement within a development or CI/CD environment, and supply chain compromise if the affected system is used for building or publishing software packages. The scope is limited to the local system (no network-based exploitation), but the impact is severe given the prevalence of npm CLI in developer and build environments (ZDI Advisory).
The ZDI published this as a 0-day advisory on January 12, 2026, after the vendor refused to patch the issue, meaning no official fix exists. The EPSS score is very low (0.000120), suggesting limited automated exploitation activity at this time. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and the ability to execute low-privileged code, which limits the attack surface compared to remote vulnerabilities (ZDI Advisory).
.js file or package.json-based package) in the attacker-writable directory that npm CLI will load before the legitimate module.npm install, npm run, or any npm lifecycle script..js, index.js, package.json) in user-writable directories that appear in npm's module resolution path; files with suspicious names mimicking legitimate npm packages in non-standard locations.cmd.exe, powershell.exe, bash) or making outbound network connections not typical of normal npm operations; unusual processes running under a higher-privileged user account shortly after npm CLI execution.node.exe or npm processes to external IPs, particularly following npm command execution.No vendor patch is available, as npm's maintainers classified the behavior as intentional design. ZDI's recommended mitigation is to restrict interaction with the npm CLI product, particularly limiting which users can execute npm commands on sensitive systems. Organizations should audit and restrict write permissions on directories included in npm's module resolution path, especially on Windows systems. Running npm CLI in isolated environments (containers, VMs) or under dedicated low-privilege service accounts with tightly controlled file system permissions can reduce the attack surface (ZDI Advisory). SUSE has issued security updates addressing this CVE in their distributions (SUSE Advisory).
ZDI published a detailed technical blog post in April 2026 titled "Node.js Trust Falls: Dangerous Module Resolution on Windows," explaining the broader class of module hijacking issues in Node.js/npm on Windows (ZDI Blog). The Hacker News weekly recap highlighted the vulnerability alongside other notable Windows security issues (The Hacker News). The security community noted frustration with npm's "by design" response, as the vendor's refusal to patch a privilege escalation flaw forced ZDI to publish a 0-day advisory after over a year of attempted coordination.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."