CVE-2026-94185 | nvm-sh nvm up to 0.40.7 Alias File Reader nvm_alias path traversal

SecurityVulns

A vulnerability categorized as problematic has been discovered in nvm-sh nvm up to 0.40.7. Affected is the function nvm_alias of the component Alias File Reader. The manipulation results in path traversal.

This vulnerability is identified as CVE-2026-94185. The attack is only possible with local access. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More