Path Traversal Vulnerability in Vaadin Affects Node.js Extraction
CVE-2026-2741

2.3LOW

Key Information:

Vendor

Vaadin

Vendor
CVE Published:
10 March 2026

What is CVE-2026-2741?

A security vulnerability in the Vaadin Framework allows specially crafted ZIP archives to escape the intended extraction directory during the automatic download and extraction of Node.js. This issue affects multiple versions and can be exploited through various attack vectors including DNS hijacking or supply chain compromises. Attackers can leverage this vulnerability to place malicious files outside the secure directory, posing a risk to the system's integrity. Users are advised to upgrade to specific patched versions or utilize a compatible preinstalled Node.js to mitigate this risk.

Affected Version(s)

flow 2.2.0 <= 2.13.0

flow 3.0.0 <= 23.6.7

flow 24.0.0 <= 24.9.9

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.