CVE-2026-58043

Summary

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under --permission, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.

This vulnerability affects Node.js main, 22.x, 24.x, and 26.x.

Affected Software

VendorProductVersion RangeStatus
nodejsnode22.23.1 <= 22.23.1affected
nodejsnode24.18.0 <= 24.18.0affected
nodejsnode26.5.0 <= 26.5.0affected

Weaknesses

  • CWE-284: CWE-284 Improper Access Control - Generic

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References