SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-56847

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A flaw in the Node.js Permission Model allows the `trace_events.createTracing().enable()` function to write trace logs outside of the intended `--allow-fs-write` boundary, potentially leading to confidentiality breaches. This issue primarily affects Node.js versions 22.x, 24.x, and 26.x, and should be prioritized by developers and system administrators using these versions in environments where sensitive data handling is critical.

CVE
CVE-2026-56847
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%

Original NVD Description

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Related CVEs

Other vulnerabilities affecting the same vendor(s)