CVE-2026-58043
7.5
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Summary
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under --permission, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
This vulnerability affects Node.js main, 22.x, 24.x, and 26.x.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nodejs | node | 22.23.1 <= 22.23.1 | affected |
| nodejs | node | 24.18.0 <= 24.18.0 | affected |
| nodejs | node | 26.5.0 <= 26.5.0 | affected |
Weaknesses
- CWE-284: CWE-284 Improper Access Control - Generic
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.