GHSA-4p3w-j4w9-5jqw

Suggest an improvement
Source
https://github.com/advisories/GHSA-4p3w-j4w9-5jqw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-4p3w-j4w9-5jqw/GHSA-4p3w-j4w9-5jqw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4p3w-j4w9-5jqw
Aliases
Published
2026-09-29T23:46:02Z
Modified
2026-09-30T00:00:03Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
moment vulnerable to Path Traversal via crafted non-string locale name
Details

Impact

moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.

This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.

Patches

This issue is patched in moment 2.31.0.

Workarounds

Validate that any user-supplied input is a string before passing it to moment.locale().

Database specific
{
    "cwe_ids":  [
        "CWE-27"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T23:46:02Z",
    "nvd_published_at":  "2026-09-15T06:16:57Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / moment

Package

Affected ranges

Type
SEMVER
Events
Introduced
2.29.2
Fixed
2.31.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-4p3w-j4w9-5jqw/GHSA-4p3w-j4w9-5jqw.json"