Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.
CVE ID: CVE-2025-4759
CVSS Base Severity: HIGH
CVSS Base Score: 8.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Vendor: n/a
Product: lockfile-lint-api
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 10.82% (scored less or equal to compared to others)
EPSS Date: 2025-06-14 (when was this score calculated)