Node.js Permission Model Flaw Allowed Bypass in Multiple Versions
CVE-2026-48617

1.8LOW

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
18 June 2026

What is CVE-2026-48617?

A vulnerability has been identified in Node.js that affects the enforcement of its permission model. Specifically, the flaw allows for a bypass via the process.report.writeReport() method due to path misvalidation. This issue can lead to potential confidentiality breaches or unauthorized access across all supported release lines including Node.js 22, 24, and 26. Best practices and timely updates are essential to safeguard applications relying on Node.js.

Affected Version(s)

node 22.22.3

node 24.16.0

node 26.3.0

References

CVSS V3.0

Score:
1.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.