Node.js File Write Bypass Vulnerability in Security Model
CVE-2026-58039
3.3LOW
What is CVE-2026-58039?
A flaw in the enforcement of the Node.js Permission Model allows for the writing and overwriting of files beyond the designated --allow-fs-write paths. This misconfiguration can potentially lead to unauthorized access to sensitive information and compromise the intended security boundaries of applications utilizing these versions of Node.js. Developers and system administrators should assess their configurations to mitigate potential risks.
Affected Version(s)
node 26.5.0
node 24.18.0
node 22.23.1
