Flaw in Node.js Permission Model Enables Unauthorized Trace Logs
CVE-2026-56847
3.3LOW
What is CVE-2026-56847?
A vulnerability in the Node.js permission model allows users to write trace logs outside designated permissions by improperly enforcing the --allow-fs-write flag. This issue can lead to unauthorized access to sensitive information, compromising the confidentiality of data under specific conditions, particularly in versions 22.x, 24.x, and 26.x. Applications utilizing these versions need immediate attention to secure their configurations.
Affected Version(s)
node 26.5.0
node 24.18.0
node 22.23.1
