Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48617

Опубликовано: 18 июн. 2026
Источник: redhat
CVSS3: 2.9
EPSS Низкий

Описание

A flaw in Node.js Permission Model enforcement allows Bypass via process.report.writeReport() Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

A flaw was found in Node.js. This vulnerability allows a bypass of the Permission Model enforcement due to path misvalidation within the process.report.writeReport() function. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access to sensitive information or other confidentiality impacts under specific configurations.

Отчет

This flaw affects Node.js's experimental Permission Model, a security feature that restricts filesystem, network, and process access when explicitly enabled via the --permission flag. Applications running with the default Node.js configuration (Permission Model not enabled) are not affected. When enabled, insufficient path validation in process.report.writeReport() could allow code running under a restricted permission scope to write a diagnostic report to a location outside the configured allow-list, resulting in low-severity information disclosure.

Меры по смягчению последствий

No workaround is available for applications that rely on the Permission Model to restrict process.report.writeReport() output paths. Users should upgrade to a fixed Node.js release (22.23.0, 24.17.0, or 26.3.1 and later) as they become available downstream.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Fix deferred
Red Hat Enterprise Linux 10nodejs24Fix deferred
Red Hat Enterprise Linux 8nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 8nodejs:24/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:24/nodejsFix deferred
Red Hat Hardened Imagesnodejs20Fix deferred
Red Hat Hardened Imagesnodejs25Fix deferred
Red Hat Hardened Imagesnodejs22-main-22.23.1-2.3.hum1FixedRHSA-2026:4538124.07.2026
Red Hat Hardened Imagesnodejs26-main-26.5.0-1.5.hum1FixedRHSA-2026:4578325.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=2490521nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation

EPSS

Процентиль: 15%
0.0024
Низкий

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 1.8
ubuntu
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 1.8
nvd
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 1.8
debian
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `proc ...

CVSS3: 1.8
github
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

suse-cvrf
около 1 месяца назад

Security update for nodejs22

EPSS

Процентиль: 15%
0.0024
Низкий

2.9 Low

CVSS3