Node.js Permission API Flaw in Node.js 26
CVE-2026-48936

3.3LOW

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-48936?

A security flaw in Node.js's Permission API allows local servers to be initiated through Unix domain sockets without the required --allow-net permission flag. This issue impacts the supported release of Node.js 26, potentially exposing applications to unauthorized access vulnerabilities. Developers and system administrators using Node.js 26 should review their permission configurations to ensure proper security measures are in place.

Affected Version(s)

node 26.3.0

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.