CVE-2021-43616
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.72%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Prueba de concepto en GitHub (no verificada) · Lista de pruebas de concepto en GitHub
⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.
Tecnologías afectadas (3)
CWE
- CWE-345
Referencias
- https://docs.npmjs.com/cli/v7/commands/npm-ci
- https://docs.npmjs.com/cli/v8/commands/npm-ci
- https://github.com/icatalina/CVE-2021-43616
- https://github.com/npm/cli/commit/457e0ae61bbc55846f5af44afa4066921923490f
- https://github.com/npm/cli/issues/2701
- https://github.com/npm/cli/issues/2701#issuecomment-972900511
- https://github.com/npm/cli/issues/2701#issuecomment-979054224
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXNVFKOF5ZYH5NIRWHKN6O6UBCHDV6FE/
- https://medium.com/cider-sec/this-time-we-were-lucky-85c0dcac94a0
- https://security.netapp.com/advisory/ntap-20211210-0002/
- https://docs.npmjs.com/cli/v7/commands/npm-ci
- https://docs.npmjs.com/cli/v8/commands/npm-ci
- https://github.com/icatalina/CVE-2021-43616
- https://github.com/npm/cli/commit/457e0ae61bbc55846f5af44afa4066921923490f
- https://github.com/npm/cli/issues/2701
- https://github.com/npm/cli/issues/2701#issuecomment-972900511
- https://github.com/npm/cli/issues/2701#issuecomment-979054224
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXNVFKOF5ZYH5NIRWHKN6O6UBCHDV6FE/
- https://medium.com/cider-sec/this-time-we-were-lucky-85c0dcac94a0
- https://security.netapp.com/advisory/ntap-20211210-0002/
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-43616",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-11-13T18:15:07.537",
"references": [
{
"url": "https://docs.npmjs.com/cli/v7/commands/npm-ci",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://docs.npmjs.com/cli/v8/commands/npm-ci",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/icatalina/CVE-2021-43616",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/cli/commit/457e0ae61bbc55846f5af44afa4066921923490f",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/cli/issues/2701",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/cli/issues/2701#issuecomment-972900511",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/cli/issues/2701#issuecomment-979054224",
"source": "cve@mitre.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXNVFKOF5ZYH5NIRWHKN6O6UBCHDV6FE/",
"source": "cve@mitre.org"
},
{
"url": "https://medium.com/cider-sec/this-time-we-were-lucky-85c0dcac94a0",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://security.netapp.com/advisory/ntap-20211210-0002/",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://docs.npmjs.com/cli/v7/commands/npm-ci",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.npmjs.com/cli/v8/commands/npm-ci",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/icatalina/CVE-2021-43616",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/cli/commit/457e0ae61bbc55846f5af44afa4066921923490f",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/cli/issues/2701",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/cli/issues/2701#issuecomment-972900511",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/cli/issues/2701#issuecomment-979054224",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXNVFKOF5ZYH5NIRWHKN6O6UBCHDV6FE/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://medium.com/cider-sec/this-time-we-were-lucky-85c0dcac94a0",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20211210-0002/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-345"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI."
},
{
"lang": "es",
"value": "** EN DISPUTA ** El comando npm ci en npm versiones 7.x y 8.x hasta 8.1.3, procede con una instalación incluso si la información de dependencia en package-lock.json difiere de package.json. Este comportamiento es incoherente con la documentación, y facilita a atacantes la instalación de malware que se supone que ha sido bloqueado por un requisito de coincidencia de versión exacta en package-lock.json. NOTA: El equipo de npm cree que esto no es una vulnerabilidad. Requeriría que alguien hiciera ingeniería social de package.json que tiene diferentes dependencias que package-lock.json. Ese usuario tendría que tener acceso al sistema de archivos o de escritura para cambiar las dependencias. El equipo de npm afirma que evitar que los actores maliciosos realicen ingeniería social u obtengan acceso al sistema de archivos está fuera del alcance de la CLI de npm"
}
],
"lastModified": "2026-06-17T04:11:12.010",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:npmjs:npm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F582C303-4B6A-4B12-9E0A-BEB12E1B93D1",
"versionEndIncluding": "7.24.2",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:npmjs:npm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DF29872C-4C3F-4DD4-ABEB-64246074752A",
"versionEndIncluding": "8.1.3",
"versionStartIncluding": "8.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netapp:next_generation_application_programming_interface:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "444CE322-1245-4EEB-A5CA-9FCB011BF531"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80E516C0-98A4-4ADE-B69F-66A772E2BAAA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}