SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58039

LOW · CVSS 3.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

A flaw in the Node.js Permission Model allows unauthorized file writes and overwrites outside of specified --allow-fs-write paths, potentially leading to confidentiality breaches or security boundary violations. Users of Node.js versions 22.x, 24.x, and 26.x should prioritize addressing this vulnerability, especially in configurations where file system access is tightly controlled.

CVE
CVE-2026-58039
Severity
LOW
CVSS
3.3
EPSS
0.15%

Original NVD Description

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.