AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-21891

HIGH · CVSS 8.8 EPSS 1.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-02-20 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. See the original NVD description below for full technical details.

CVE
CVE-2024-21891
Severity
HIGH
CVSS
8.8
EPSS
1.24%

Original NVD Description

Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Related CVEs

Other vulnerabilities affecting the same vendor(s)