Описание
A flaw in Node.js Permission Model enforcement allows Bypass via process.report.writeReport() Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
A flaw was found in Node.js. This vulnerability allows a bypass of the Permission Model enforcement due to path misvalidation within the process.report.writeReport() function. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access to sensitive information or other confidentiality impacts under specific configurations.
Отчет
This flaw affects Node.js's experimental Permission Model, a security feature that restricts filesystem, network, and process access when explicitly enabled via the --permission flag. Applications running with the default Node.js configuration (Permission Model not enabled) are not affected. When enabled, insufficient path validation in process.report.writeReport() could allow code running under a restricted permission scope to write a diagnostic report to a location outside the configured allow-list, resulting in low-severity information disclosure.
Меры по смягчению последствий
No workaround is available for applications that rely on the Permission Model to restrict process.report.writeReport() output paths. Users should upgrade to a fixed Node.js release (22.23.0, 24.17.0, or 26.3.1 and later) as they become available downstream.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nodejs22 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | nodejs24 | Fix deferred | ||
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Fix deferred | ||
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Fix deferred | ||
| Red Hat Enterprise Linux 9 | nodejs:22/nodejs | Fix deferred | ||
| Red Hat Enterprise Linux 9 | nodejs:24/nodejs | Fix deferred | ||
| Red Hat Hardened Images | nodejs20 | Fix deferred | ||
| Red Hat Hardened Images | nodejs25 | Fix deferred | ||
| Red Hat Hardened Images | nodejs22-main-22.23.1-2.3.hum1 | Fixed | RHSA-2026:45381 | 24.07.2026 |
| Red Hat Hardened Images | nodejs26-main-26.5.0-1.5.hum1 | Fixed | RHSA-2026:45783 | 25.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.9 Low
CVSS3
Связанные уязвимости
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js Permission Model enforcement allows Bypass via `proc ...
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
EPSS
2.9 Low
CVSS3