File Metadata Modification Risk in Node.js by NodeSource
CVE-2026-48935

3.3LOW

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-48935?

A security flaw in the Node.js Permission API allows modifications to file metadata even when permissions are set to read-only using options such as --allow-fs-read. This vulnerability is present in all supported release lines of Node.js, including versions 22, 24, and 26, potentially exposing systems to unauthorized changes and data integrity issues.

Affected Version(s)

node 22.22.3

node 24.16.0

node 26.3.0

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.