CVE-2026-0775: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-0775 is a local privilege escalation vulnerability in npm CLI, classified as an "Uncontrolled Search Path Element" flaw (also described as Incorrect Permission Assignment for Critical Resource, CWE-732). It allows local attackers with low-privileged code execution to escalate privileges and execute arbitrary code in the context of a target user by exploiting insecure module loading. The vulnerability was reported to npm on November 13, 2024; the vendor deemed it "by design" and declined to patch it, leading ZDI to publish a 0-day advisory on January 12, 2026. The CVSS v3 base score is 7.0–7.8 HIGH (ZDI assigned 7.8 with AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) (ZDI Advisory).

Technical details

The root cause is CWE-732 (Incorrect Permission Assignment for Critical Resource), specifically an uncontrolled search path element in npm CLI's module resolution logic. When npm CLI loads modules, it references an unsecured or attacker-writable directory location, allowing a low-privileged attacker to plant a malicious module that gets loaded in place of the legitimate one. This is a DLL/module hijacking-style attack applicable on Windows systems where npm resolves modules from paths that can be influenced by unprivileged users. The vendor acknowledged the report but classified the behavior as intentional design, and no patch has been issued; ZDI published the advisory (ZDI-CAN-25430) as a 0-day after exhausting coordinated disclosure efforts (ZDI Advisory, ZDI Blog).

Impact

Successful exploitation grants the attacker full confidentiality, integrity, and availability impact on the affected system, as they can execute arbitrary code in the context of the target user running npm CLI. This could enable credential theft, installation of persistent malware, lateral movement within a development or CI/CD environment, and supply chain compromise if the affected system is used for building or publishing software packages. The scope is limited to the local system (no network-based exploitation), but the impact is severe given the prevalence of npm CLI in developer and build environments (ZDI Advisory).

Exploitability

The ZDI published this as a 0-day advisory on January 12, 2026, after the vendor refused to patch the issue, meaning no official fix exists. The EPSS score is very low (0.000120), suggesting limited automated exploitation activity at this time. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and the ability to execute low-privileged code, which limits the attack surface compared to remote vulnerabilities (ZDI Advisory).

Exploitation steps

  1. Gain local access: Obtain the ability to execute low-privileged code on the target Windows system where npm CLI is installed (e.g., via phishing, existing foothold, or shared system access).
  2. Identify vulnerable module search paths: Analyze npm CLI's module resolution order to identify directories in the search path that are writable by low-privileged users (e.g., user-writable directories that appear before system directories in the resolution order).
  3. Plant malicious module: Place a crafted malicious Node.js module (e.g., a .js file or package.json-based package) in the attacker-writable directory that npm CLI will load before the legitimate module.
  4. Trigger npm CLI execution: Wait for or cause the target user (with higher privileges) to run an npm CLI command that triggers module loading, such as npm install, npm run, or any npm lifecycle script.
  5. Achieve privilege escalation: The malicious module is loaded and executed in the context of the target user, granting the attacker code execution at the target's privilege level (ZDI Advisory, ZDI Blog).

Indicators of compromise

  • File System: Unexpected or newly created Node.js module files (.js, index.js, package.json) in user-writable directories that appear in npm's module resolution path; files with suspicious names mimicking legitimate npm packages in non-standard locations.
  • Process: npm CLI spawning unexpected child processes (e.g., cmd.exe, powershell.exe, bash) or making outbound network connections not typical of normal npm operations; unusual processes running under a higher-privileged user account shortly after npm CLI execution.
  • Logs: System event logs showing process creation events where npm or Node.js spawns privileged subprocesses; audit logs recording file creation in npm module directories by low-privileged accounts.
  • Network: Unexpected outbound connections from node.exe or npm processes to external IPs, particularly following npm command execution.

Mitigation and workarounds

No vendor patch is available, as npm's maintainers classified the behavior as intentional design. ZDI's recommended mitigation is to restrict interaction with the npm CLI product, particularly limiting which users can execute npm commands on sensitive systems. Organizations should audit and restrict write permissions on directories included in npm's module resolution path, especially on Windows systems. Running npm CLI in isolated environments (containers, VMs) or under dedicated low-privilege service accounts with tightly controlled file system permissions can reduce the attack surface (ZDI Advisory). SUSE has issued security updates addressing this CVE in their distributions (SUSE Advisory).

Community reactions

ZDI published a detailed technical blog post in April 2026 titled "Node.js Trust Falls: Dangerous Module Resolution on Windows," explaining the broader class of module hijacking issues in Node.js/npm on Windows (ZDI Blog). The Hacker News weekly recap highlighted the vulnerability alongside other notable Windows security issues (The Hacker News). The security community noted frustration with npm's "by design" response, as the vendor's refusal to patch a privilege escalation flaw forced ZDI to publish a 0-day advisory after over a year of attempted coordination.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

npm

Affected

sid

npm

Affected

trixie

npm

Affected

Ubuntu

Unknown

bionic (esm-apps)

npm

Unknown

devel

npm

Unknown

focal (esm-apps)

npm

Unknown

jammy

npm

Unknown

jammy (esm-apps)

npm

Unknown

noble

npm

Unknown

noble (esm-apps)

npm

Unknown

resolute

npm

Unknown

Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management