{"id":"CVE-2022-0144","title":"shelljs is vulnerable to Improper Privilege Management","summary":"shelljs is vulnerable to Improper Privilege Management","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-269"],"vendor":"shelljs_project","product":"shelljs","affected":["shelljs < 0.8.5"],"patched":["shelljs 0.8.5"],"published":"2022-01-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:14.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-0144","references":[{"url":"https://github.com/shelljs/shelljs/commit/d919d22dd6de385edaa9d90313075a77f74b338c","label":"security@huntr.dev"},{"url":"https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c","label":"security@huntr.dev"},{"url":"https://github.com/shelljs/shelljs/commit/d919d22dd6de385edaa9d90313075a77f74b338c","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00427,"epssPercentile":0.34977,"ingestedAt":"2026-10-08T23:16:47.328Z","slug":"CVE-2022-0144","body":"## Overview\n\nshelljs is vulnerable to Improper Privilege Management\n\n## Affected\n\n- `shelljs < 0.8.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `shelljs 0.8.5`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}