Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48617

Опубликовано: 18 июн. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsfixed24.17.0+dfsg+~cs24.13.2-1package
nodejsnot-affectedbookwormpackage
nodejsnot-affectedbullseyepackage

Примечания

  • https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#permission-model-bypass-via-processreportwritereport-path-misvalidation-cve-2026-48617---low

  • https://github.com/nodejs/node/commit/2f62693801a12bc8a485b3b7da3239ac522f607d (v22.23.0)

EPSS

Процентиль: 15%
0.0024
Низкий

Связанные уязвимости

CVSS3: 1.8
ubuntu
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 2.9
redhat
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 1.8
nvd
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 1.8
github
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

suse-cvrf
около 1 месяца назад

Security update for nodejs22

EPSS

Процентиль: 15%
0.0024
Низкий