CVE-2025-59330

Description

A flaw was found in error-ex. This vulnerability allows for cryptocurrency transaction redirection via an npm account takeover and the publication of a malicious package version.

Statement

No Red Hat products use any compromised version of the impacted package(s). For more details see https://access.redhat.com/security/supply-chain-attacks-NPM-packages

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability

Technical Impact: Execute Unauthorized Code or Commands

Frequently Asked Questions

Want to get errata notifications? Sign up here.