CyberRota Analysis
AI-GeneratedA flaw in the Node.js Permission Model allows attackers to exploit boundary handling when using the `--permission` flag, potentially granting them unauthorized access to read from or write to filesystem paths outside the designated allowlist. This vulnerability poses a significant risk to applications leveraging Node.js versions 22.x, 24.x, and 26.x, and should be prioritized by developers and system administrators using these versions to mitigate potential data breaches or unauthorized access.
Original NVD Description
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
Related CVEs
Other vulnerabilities affecting the same vendor(s)