
CVE-2026-1665 A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() function uses eval to execute wget commands, and th… https://www.cve.org/CVERecord?id=CVE-2026-1665
Post summary
The entry announces a command‑injection flaw in Node Version Manager versions 0.40.3 and older, detailing how the nvm_download() function improperly evaluates wget commands.

