Overview
About vulnerability
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under --permission, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
This vulnerability affects Node.js main, 22.x, 24.x, and 26.x.
Details
- Affected product:
- AlmaLinux 9.2 ESU , Alpine Linux 3.23 , Alpine Linux 3.24 , Debian 10 , Debian 11 , Debian 12 , Debian 13 , EL 10 , EL 6 , EL 7 , EL 8 , EL 9 , TuxCare 9.6 ESU , Ubuntu 18.04 , Ubuntu 20.04 , Ubuntu 22.04 , Ubuntu 24.04
- Affected packages:
- alt-nodejs20 @ 20.20.2 (+94 more)