Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56847

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js 22.x, 24.x, and 26.x.

A flaw in the Node.js Permission Model allows trace_events.createTracing().enable() to bypass --allow-fs-write restrictions and write trace logs outside intended paths, potentially leading to unauthorized information disclosure.

Отчет

This Low impact flaw in Node.js allows a local attacker to bypass filesystem write restrictions for trace logs when using trace_events.createTracing().enable(). This limited integrity impact permits specific log files to be written outside the intended --allow-fs-write boundary.

Меры по смягчению последствий

Avoid using the trace_events.createTracing().enable() function in environments that rely on the Node.js Permission Model for file system isolation. Be aware that avoiding this function disables dynamic trace log generation, which may impact performance profiling, APM monitoring, and diagnostic workflows.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Fix deferred
Red Hat Enterprise Linux 10nodejs24Fix deferred
Red Hat Enterprise Linux 8nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 8nodejs:24/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:24/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:26/nodejsFix deferred
Red Hat Hardened Imagesnodejs20Not affected
Red Hat Hardened Imagesnodejs25Not affected
Red Hat Hardened Imagesnodejs26-main-26.5.1-1.5.hum1FixedRHSA-2026:4827329.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2509178nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions

EPSS

Процентиль: 5%
0.00158
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS3: 6.1
nvd
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS3: 3.3
msrc
около 1 месяца назад

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS3: 6.1
debian
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...

CVSS3: 3.3
github
около 2 месяцев назад

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

EPSS

Процентиль: 5%
0.00158
Низкий

3.3 Low

CVSS3