A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
CVSS Details
- CVSS 3.0 Base Score: 2.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nodejs-develUpgrade nodejs-nodemonUpgrade npmUpgrade nodejs-docsUpgrade nodejsUpgrade nodejs-full-i18nUpgrade nodejs-packagingUpgrade nodejs-packaging-bundler | Aug 28, 2024 | Jul 10, 2024 |
| Alpine Linux | — | Upgrade nodejs | Aug 22, 2024 | Jul 10, 2024 |
| Amazon_linux_2023 | — | Upgrade nodejs20-full-i18nUpgrade nodejs20-debugsourceUpgrade v8-11.3-develUpgrade nodejs20-debuginfoUpgrade nodejs20-npmUpgrade nodejs20-docsUpgrade nodejs20Upgrade nodejs20-develUpgrade nodejs20-libsUpgrade nodejs20-libs-debuginfo | Feb 17, 2025 | Jul 10, 2024 |
| Debian | — | Upgrade nodejs | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | May 15, 2025 | Jul 10, 2024 |
| Oracle_linux | — | Upgrade nodejs-docsUpgrade nodejs-full-i18nUpgrade nodejs-nodemonUpgrade nodejsUpgrade nodejs-develUpgrade nodejs-packagingUpgrade nodejs-packaging-bundlerUpgrade npm | Oct 16, 2024 | Jul 10, 2024 |
| Redhat_linux | — | Upgrade nodejs-nodemonUpgrade nodejs-develUpgrade nodejs-docsUpgrade nodejs-debugsourceUpgrade nodejs-packaging-bundlerUpgrade nodejs-full-i18nUpgrade nodejs-debuginfoUpgrade nodejsUpgrade npmUpgrade nodejs-packaging | Sep 13, 2024 | Jul 10, 2024 |
| Rocky_linux | — | Upgrade nodejs-debugsourceUpgrade nodejs-full-i18nUpgrade nodejsUpgrade nodejs-develUpgrade npmUpgrade nodejs-debuginfo | Sep 17, 2024 | Jul 10, 2024 |
| Suse | — | Upgrade npm20Upgrade npm22Upgrade nodejs22-docsUpgrade nodejs20-docsUpgrade nodejs22Upgrade nodejs22-develUpgrade corepack22Upgrade nodejs20Upgrade corepack20Upgrade nodejs20-devel | Jul 18, 2024 | Jul 10, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 10, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub