It was found that node-cli insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to. lock_file = '/tmp/' + cli.app + '.pid', log_file = '/tmp/' + cli.app + '.log'; External References: https://nodesecurity.io/advisories/95
Created nodejs-cli tracking bugs for this issue: Affects: fedora-all [bug 1347226] Affects: epel-all [bug 1347227]
CVE assignment: https://github.com/distributedweaknessfiling/DWF-Database/commit/5e607a0cad2769db2be5aafc4d9b1ec49bd7bbbc