Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94346.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94346
Upstream
Published
2026-07-30T06:25:55Z
Modified
2026-08-28T17:47:40.868642524Z
Summary
CVE-2026-58043 affecting package nodejs for versions less than 24.18.1-1
Details

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under --permission, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.

This vulnerability affects Node.js main, 22.x, 24.x, and 26.x.

References

Affected packages

Azure Linux:3 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/azure-linux/nodejs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.18.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94346.json"