BIT-node-2026-58043

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/node/BIT-node-2026-58043.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-node-2026-58043
Aliases
Published
2026-08-17T05:52:33.742Z
Modified
2026-08-17T08:11:07.011984386Z
Summary
[none]
Details

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under --permission, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.

This vulnerability affects Node.js main, 22.x, 24.x, and 26.x.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / node

Package

Name
node
Purl
pkg:bitnami/node

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.23.2
Introduced
23.0.0
Fixed
24.18.1
Introduced
25.0.0
Fixed
26.5.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/node/BIT-node-2026-58043.json"