StackRadar

CVE-2019-16777

High

Advisory

Published 13 Dec 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.020
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
1 of 2
affected packages

npm Vulnerable to Global node_modules Binary Overwrite

Carried by container images the latest versions of 59 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
npmnpm1.0.1, 1.39.1-prel, 3.5.2, 3.10.3+13 more6.13.453
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2no fix listed6
OSV records
GHSA-4328-8hgf-7wjrUBUNTU-CVE-2019-16777

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
npm@3.5.2
no fix listed
6.13.4

Open the chart page →

36,215
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
npm@6.12.0
6.13.4

Open the chart page →

1,986
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
npm@6.9.0
6.13.4

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
npm@6.9.0
6.13.4

Open the chart page →

20,462
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
npm@6.12.0
6.13.4

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
npm@6.12.0
6.13.4

Open the chart page →

29,220
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
npm@6.4.1
6.13.4

Open the chart page →

4,967
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed

Open the chart page →

10,902
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
npm@6.5.0-next.0
6.13.4

Open the chart page →

1,309

Container images carrying it

56 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
npm@5.6.0
6.13.4
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
npm@5.6.0
6.13.4
4
governify/assets-manager:v1.4.12987672448c7
npm@1.39.1-prel
6.13.4
2
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
npm@6.9.0
6.13.4
2
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
npm@6.9.0
6.13.4
2
migmartri/prerender:latest486aacfd5aa9
npm@4.2.0
6.13.4
2
statsd/statsd:v0.8.6dab129e74c25
npm@6.4.1
6.13.4
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
npm@6.12.0
6.13.4
2
a5hut0sh/helloworld:1.02ae77620e616
npm@6.5.0-next.0
6.13.4
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
npm@6.12.1
6.13.4
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
npm@6.1.0
6.13.4
1
codercom/code-server:4.11.0-debian1e2cc688008e
npm@1.0.1
6.13.4
1
codercom/code-server:3.10.247605610ad8d
npm@1.0.1
6.13.4
1
daskdev/dask-notebook:1.1.0052630f5ca04
npm@5.6.0
6.13.4
1
decayofmind/hubot:3.3.21e18e92fe694
npm@6.9.0
6.13.4
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
npm@5.10.0
6.13.4
1
devspacecloud/ui:0.3.3deef55ff29a7
npm@6.7.0
6.13.4
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
npm@5.6.0
no fix listed
6.13.4
1
galaxy/galaxy-init:v18.010267bad550e6
npm@5.6.0
6.13.4
1
halkeye/irslackd:latest7638bfba70b0
npm@6.4.1
6.13.4
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
npm@5.6.0
6.13.4
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
npm@6.4.1
6.13.4
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
npm@5.6.0
6.13.4
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
npm@5.6.0
6.13.4
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
npm@6.4.1
6.13.4
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
npm@6.4.1
6.13.4
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
npm@6.4.1
6.13.4
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
npm@5.6.0
6.13.4
1
ibmcom/microclimate-portal:latested5505e5c7ec
npm@5.6.0
6.13.4
1
ibmcom/microclimate-theia:lateste17bdccc5030
npm@5.6.0
6.13.4
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
npm@6.4.1
6.13.4
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
npm@3.10.10
6.13.4
1
jupyterhub/jupyterhub:5.4.63974ba945e65
npm@9.2.0~ds1-2
no fix listed
1
koumoul/capture:17108d47be3b2
npm@6.12.0
6.13.4
1
koumoul/openapi-viewer:18eeca2e8285b
npm@5.5.1
6.13.4
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
npm@6.9.0
6.13.4
1
lavandadelpatio/frontend:latest501c3f31e0bc
npm@6.7.0
6.13.4
1
linuxserver/cloud9:latest45c5fe102ff3
npm@3.10.3
6.13.4
1
linuxserver/code-server:4.10.1a5e43a05ae79
npm@1.0.1
6.13.4
1
logentries/docker-logentries:0.2.1f1f90a236998
npm@3.10.9
6.13.4
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
npm@6.14.4+ds-1ubuntu2
no fix listed
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
npm@3.10.10
6.13.4
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
npm@3.10.10
6.13.4
1
minddocdev/hubot:0.1.96c60b11a4fa7
npm@6.4.1
6.13.4
1
muluder/prograncontrollermcord:0.1.843b597a93da7
npm@5.6.0
6.13.4
1
nodered/node-red-docker:0.19.6-v8070643219ea2
npm@6.4.1
6.13.4
1
omecproject/onos-progran:1.0.05715e5648aa0
npm@5.6.0
6.13.4
1
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
npm@3.5.2
no fix listed
6.13.4
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
npm@3.5.2
no fix listed
6.13.4
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
npm@6.12.0
6.13.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.