A vulnerability, which was classified as critical, was found in raineorshine npm-check-updates up to 23.0.2. The impacted element is an unknown function of the file package.json. The manipulation results in injection.

This vulnerability is known as CVE-2026-73035. It is possible to launch the attack remotely. No exploit is available.

It is advisable to implement a patch to correct this issue.