moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.
This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.
This issue is patched in moment 2.31.0.
Validate that any user-supplied input is a string before passing it to moment.locale().
{
"cwe_ids": [
"CWE-27"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T23:46:02Z",
"nvd_published_at": "2026-09-15T06:16:57Z",
"severity": "MODERATE"
}