| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2xx6-qf7x-grqh | next-npm-version is vulnerable to Command injection |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 09 May 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in npm next-npm-version Package |
Sat, 09 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in next-npm-version 1.0.1 | |
| Weaknesses | CWE-78 |
Fri, 08 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Afeiship
Afeiship next-npm-version |
|
| Vendors & Products |
Afeiship
Afeiship next-npm-version |
Thu, 07 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in next-npm-version 1.0.1 | |
| Weaknesses | CWE-78 |
Thu, 07 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NPM package next-npm-version1.0.1 is vulnerable to Command injection. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-08T22:08:39.247Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63706
Updated: 2026-05-08T22:08:30.881Z
Status : Deferred
Published: 2026-05-07T15:16:04.820
Modified: 2026-05-08T23:16:34.450
Link: CVE-2025-63706
No data.
OpenCVE Enrichment
Updated: 2026-05-09T02:15:06Z
Github GHSA