Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv82-5vqw-69hj

Опубликовано: 18 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 1.8

Описание

A flaw in Node.js Permission Model enforcement allows Bypass via process.report.writeReport() Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

A flaw in Node.js Permission Model enforcement allows Bypass via process.report.writeReport() Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

EPSS

Процентиль: 15%
0.0024
Низкий

1.8 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 1.8
ubuntu
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 2.9
redhat
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 1.8
nvd
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 1.8
debian
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `proc ...

suse-cvrf
около 1 месяца назад

Security update for nodejs22

EPSS

Процентиль: 15%
0.0024
Низкий

1.8 Low

CVSS3

Дефекты

CWE-284