Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-58039

Опубликовано: 31 июл. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsunfixedpackage

Примечания

  • https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-process-reports-to-write-outside-the-allowlist-cve-2026-58039---low

EPSS

Процентиль: 7%
0.00175
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
7 дней назад

(A flaw in Node.js Permission Model enforcement allows process.report w ...)

CVSS3: 4.4
redhat
7 дней назад

A flaw was found in Node.js. The permission model enforcement, specifically related to `process.report` functionality, allows an attacker to write or overwrite files in locations outside of the intended secure paths. This vulnerability can lead to the disclosure of sensitive information or bypass the security boundaries designed to protect the system.

CVSS3: 3.3
nvd
7 дней назад

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS3: 3.3
github
7 дней назад

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

EPSS

Процентиль: 7%
0.00175
Низкий