Node.js File Write Bypass Vulnerability in Security Model
CVE-2026-58039

3.3LOW

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-58039?

A flaw in the enforcement of the Node.js Permission Model allows for the writing and overwriting of files beyond the designated --allow-fs-write paths. This misconfiguration can potentially lead to unauthorized access to sensitive information and compromise the intended security boundaries of applications utilizing these versions of Node.js. Developers and system administrators should assess their configurations to mitigate potential risks.

Affected Version(s)

node 26.5.0

node 24.18.0

node 22.23.1

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.