Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-43616 — Demonstration of CVE-2021-43616: npm `ci` command ignoring package-lock.json, causing unintended dependency version installation and supply-chain risk. | Kitploit
Tools/GitHubGitHub/icatalina/cve-2021-43616
Vulnerability AnalysisSupply Chain SecurityLearning & Education
GitHubicatalina/cve-2021-43616

CVE-2021-43616

Demonstration of CVE-2021-43616: npm `ci` command ignoring package-lock.json, causing unintended dependency version installation and supply-chain risk.

View Repository
394 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701

Remove the node_modules folder and run npx npm@8 ci, you can see how npm will install version 2.2.x (2.2.16 at the time of this commit) even though package-lock.json requires 2.0.0

cat node_modules/shortid/package.json

I've commited the node_modules from the original install so the issue is obvious after running npm ci

Download Tool