A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
CVSS Details
- CVSS 3.0 Base Score: 2.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nodejs-full-i18nUpgrade nodejs-packaging-bundlerUpgrade nodejsUpgrade nodejs-packagingUpgrade nodejs-develUpgrade npmUpgrade nodejs-docsUpgrade nodejs-nodemon | Aug 28, 2024 | Jul 10, 2024 |
| Alpine Linux | — | Upgrade nodejs | Aug 22, 2024 | Jul 10, 2024 |
| Amazon_linux_2023 | — | Upgrade v8-11.3-develUpgrade nodejs20-libsUpgrade nodejs20-npmUpgrade nodejs20-develUpgrade nodejs20-debuginfoUpgrade nodejs20-docsUpgrade nodejs20 | Feb 17, 2025 | Jul 10, 2024 |
| Debian | — | Upgrade nodejs | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | May 15, 2025 | Jul 10, 2024 |
| Oracle_linux | — | Upgrade nodejs-packaging-bundlerUpgrade npmUpgrade nodejs-packagingUpgrade nodejsUpgrade nodejs-docsUpgrade nodejs-develUpgrade nodejs-nodemonUpgrade nodejs-full-i18n | Oct 16, 2024 | Jul 10, 2024 |
| Redhat_linux | — | Upgrade nodejs-nodemonUpgrade nodejs-develUpgrade nodejs-debugsourceUpgrade nodejs-docsUpgrade nodejs-full-i18nUpgrade nodejs-debuginfoUpgrade nodejs-packaging-bundlerUpgrade npmUpgrade nodejsUpgrade nodejs-packaging | Sep 13, 2024 | Jul 10, 2024 |
| Rocky_linux | — | Upgrade npmUpgrade nodejs-debuginfoUpgrade nodejs-develUpgrade nodejs-full-i18nUpgrade nodejsUpgrade nodejs-debugsource | Sep 17, 2024 | Jul 10, 2024 |
| Suse | — | Upgrade nodejs20Upgrade corepack20Upgrade corepack22Upgrade nodejs20-develUpgrade nodejs22-develUpgrade nodejs20-docsUpgrade nodejs22Upgrade nodejs22-docsUpgrade npm22Upgrade npm20 | Jul 18, 2024 | Jul 10, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 10, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub