StackRadar

CVE-2021-39135

High

Advisory

Published 31 Aug 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.006
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 17,781 indexed, latest versions
Container images
30
deployed by those charts
Fix available
2 of 3
affected packages

UNIX Symbolic Link (Symlink) Following in @npmcli/arborist

Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 30 images.

Affected packageAffected versionsFixed inImages
@npmcli/arboristnpm1.0.8, 2.1.1, 2.2.5, 2.2.9+7 more2.8.220
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2no fix listed5
nodejsapk12.17.0-r0, 12.18.4-r0, 12.20.1-r0, 12.22.4-r0+1 more12.22.6-r0, 14.17.6-r07
OSV records
ALPINE-CVE-2021-39135GHSA-gmw6-94gg-2rc2UBUNTU-CVE-2021-39135

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
nodejs@12.17.0-r0
12.22.6-r0

Open the chart page →

30,326
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
@npmcli/arborist@2.2.5
2.8.2

Open the chart page →

3,476
laravelrenoki-co1.0.01 of 2See more

laravel renoki-co 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
@npmcli/arborist@2.6.2
nodejs@14.17.4-r0
2.8.2
14.17.6-r0

Open the chart page →

6,931
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
@npmcli/arborist@2.8.0
2.8.2

Open the chart page →

24,488
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
@npmcli/arborist@2.4.1
2.8.2

Open the chart page →

1,972
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
@npmcli/arborist@2.1.1
2.8.2

Open the chart page →

9,971
foundryvttgeek-cookbookVerified publisher3.4.21 of 1See more

foundryvtt geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
felddy/foundryvtt:0.8.36c5d90b90349
@npmcli/arborist@2.4.1
2.8.2

Open the chart page →

2,042
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
nodejs@12.20.1-r0
12.22.6-r0

Open the chart page →

4,410
docker-registry-browsergmelilloVerified publisher0.1.21 of 1See more

docker-registry-browser gmelillo 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
klausmeyer/docker-registry-browser:1.3.5430a440d95af
nodejs@12.18.4-r0
12.22.6-r0

Open the chart page →

4,108
laravel-octanerenoki-co1.0.01 of 1See more

laravel-octane renoki-co 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
nodejs@12.22.4-r0
12.22.6-r0

Open the chart page →

3,634
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
nodejs@12.20.1-r0
12.22.6-r0

Open the chart page →

7,517
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
@npmcli/arborist@2.6.2
2.8.2

Open the chart page →

5,507
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
no fix listed

Open the chart page →

12,779
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
no fix listed

Open the chart page →

27,417
flaresolverrgeek-cookbookVerified publisher5.4.21 of 1See more

flaresolverr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
@npmcli/arborist@1.0.8
2.8.2

Open the chart page →

1,870
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
@npmcli/arborist@2.5.0
2.8.2

Open the chart page →

2,000
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
@npmcli/arborist@2.6.1
2.8.2

Open the chart page →

2,000
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
@npmcli/arborist@2.7.1
2.8.2

Open the chart page →

4,591
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
frappe/frappe-socketio:v13.4.12095767a9e82
@npmcli/arborist@2.6.1
2.8.2

Open the chart page →

6,501
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
@npmcli/arborist@2.6.2
2.8.2

Open the chart page →

2,581
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
@npmcli/arborist@2.6.2
2.8.2

Open the chart page →

4,667
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
npm@6.14.4+ds-1ubuntu2
no fix listed

Open the chart page →

17,779
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
@npmcli/arborist@2.6.4
2.8.2

Open the chart page →

5,287
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
@npmcli/arborist@2.6.4
2.8.2
socialmediamacroscope/smile_server:0.3.31a528c794270
@npmcli/arborist@2.6.4
2.8.2

Open the chart page →

109,294
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
no fix listed

Open the chart page →

36,215
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
@npmcli/arborist@2.6.2
nodejs@14.17.4-r0
2.8.2
14.17.6-r0

Open the chart page →

5,687
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
@npmcli/arborist@2.2.9
2.8.2

Open the chart page →

3,696
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed

Open the chart page →

10,902
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-39135.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
@npmcli/arborist@2.2.9
2.8.2

Open the chart page →

2,559

Container images carrying it

30 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
@npmcli/arborist@2.4.1
2.8.2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
@npmcli/arborist@2.8.0
2.8.2
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
no fix listed
1
felddy/foundryvtt:0.8.36c5d90b90349
@npmcli/arborist@2.4.1
2.8.2
1
frappe/frappe-socketio:v13.4.12095767a9e82
@npmcli/arborist@2.6.1
2.8.2
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
nodejs@12.17.0-r0
12.22.6-r0
1
jesec/flood:4.6.060bd59cfb4eb
@npmcli/arborist@2.5.0
2.8.2
1
jesec/rtorrent-flood:latestf0c894ec459e
@npmcli/arborist@2.6.1
2.8.2
1
klausmeyer/docker-registry-browser:1.3.5430a440d95af
nodejs@12.18.4-r0
12.22.6-r0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
npm@6.14.4+ds-1ubuntu2
no fix listed
1
milesmcc/shynet:v0.13.1ba54f7797a6b
@npmcli/arborist@2.6.2
2.8.2
1
milesmcc/shynet:v0.12.0e821e31140f7
@npmcli/arborist@2.6.2
2.8.2
1
ondrejsika/parking:latestb1fd497416c8
@npmcli/arborist@2.2.9
2.8.2
1
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
no fix listed
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
no fix listed
1
shinobisystems/shinobi:dev3ca746937856
@npmcli/arborist@2.7.1
2.8.2
1
shinobisystems/shinobi:latestc2f5ce2e1067
@npmcli/arborist@2.6.2
2.8.2
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
@npmcli/arborist@2.6.4
2.8.2
1
socialmediamacroscope/smile_server:0.3.31a528c794270
@npmcli/arborist@2.6.4
2.8.2
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed
1
testhubio/testhub-frontend:on-preme86c2db53be8
nodejs@12.20.1-r0
12.22.6-r0
1
tzahi12345/youtubedl-material:4.23720b856bd2f
nodejs@12.20.1-r0
12.22.6-r0
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
@npmcli/arborist@2.2.5
2.8.2
1
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
@npmcli/arborist@1.0.8
2.8.2
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
@npmcli/arborist@2.6.4
2.8.2
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
@npmcli/arborist@2.2.9
2.8.2
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
@npmcli/arborist@2.1.1
2.8.2
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
@npmcli/arborist@2.6.2
nodejs@14.17.4-r0
2.8.2
14.17.6-r0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
@npmcli/arborist@2.6.2
nodejs@14.17.4-r0
2.8.2
14.17.6-r0
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
nodejs@12.22.4-r0
12.22.6-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.