FlawAtlas
Search the atlas
CVE-2019-15119 Moderate

cnlh nps vulnerable to file overwrite by local user in github.com/cnlh/nps

cnlh nps vulnerable to file overwrite by local user in github.com/cnlh/nps

Exploit probability 1.0%
Published April 22, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

44 explicit affected versions

Go github.com/cnlh/nps
Go ehang.io/nps

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-15119

lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.

View original source
Open Source Vulnerabilities GO-2025-3625

cnlh nps vulnerable to file overwrite by local user in github.com/cnlh/nps

View original source
Open Source Vulnerabilities GHSA-2vp2-8m5j-4rjx

`lib/install/install.go` in cnlh nps prior to 0.23.2 uses 0777 permissions for `/usr/local/bin/nps and/or /usr/bin/nps`, leading to a file overwrite by a local user.

View original source

05 / REFERENCES

Further evidence