Description
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A malicious website could use a DNS rebinding attack to trick the web browser to bypass same-origin-policy checks and to allow HTTP connections to localhost or to hosts on the local network. If a Node.js process with the debug port active is running on localhost or on a host on the local network, the malicious website could connect to it as a debugger, and get full code execution access.
Published: 2018-05-17
Score: 8.8 High
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-5619 The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A malicious website could use a DNS rebinding attack to trick the web browser to bypass same-origin-policy checks and to allow HTTP connections to localhost or to hosts on the local network. If a Node.js process with the debug port active is running on localhost or on a host on the local network, the malicious website could connect to it as a debugger, and get full code execution access.
Github GHSA Github GHSA GHSA-wq4c-wm6x-jw44 Withdrawn Advisory: Node.js Inspector RCE via DNS Rebinding
Ubuntu USN Ubuntu USN USN-4796-1 Node.js vulnerabilities
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01169}

epss

{'score': 0.01088}


Subscriptions

Nodejs Node.js
Redhat Rhel Software Collections
cve-icon MITRE

Status: PUBLISHED

Assigner: nodejs

Published:

Updated: 2024-09-17T01:35:37.449Z

Reserved: 2018-02-15T00:00:00.000Z

Link: CVE-2018-7160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-17T14:29:00.827

Modified: 2024-11-21T04:11:42.010

Link: CVE-2018-7160

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-03-08T00:00:00Z

Links: CVE-2018-7160 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses