Flaw in Node.js Permission Model Enables Unauthorized Trace Logs
CVE-2026-56847

3.3LOW

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-56847?

A vulnerability in the Node.js permission model allows users to write trace logs outside designated permissions by improperly enforcing the --allow-fs-write flag. This issue can lead to unauthorized access to sensitive information, compromising the confidentiality of data under specific conditions, particularly in versions 22.x, 24.x, and 26.x. Applications utilizing these versions need immediate attention to secure their configurations.

Affected Version(s)

node 26.5.0

node 24.18.0

node 22.23.1

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.