← Back to CVE List
CVE-2026-58043NVD
Vulnerability Summary
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
CVSS v3.1 Base Metrics — Score 8.4 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- Nodejs Node.js >= 22.0 and <= 22.23.1
- Nodejs Node.js >= 24.0.0 and <= 24.18.0
- Nodejs Node.js >= 26.0.0 and <= 26.5.0
Not provided by NVD for this CVE.