A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
CVSS Details
- CVSS 3.0 Base Score: 2.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nodejs-full-i18nUpgrade nodejsUpgrade nodejs-packagingUpgrade nodejs-packaging-bundlerUpgrade nodejs-docsUpgrade nodejs-nodemonUpgrade npmUpgrade nodejs-devel | Aug 28, 2024 | Jul 10, 2024 |
| Alpine Linux | — | Upgrade nodejs | Aug 22, 2024 | Jul 10, 2024 |
| Amazon_linux_2023 | — | Upgrade nodejs20-debugsourceUpgrade nodejs20-full-i18nUpgrade nodejs20-libs-debuginfoUpgrade nodejs20-docsUpgrade nodejs20-debuginfoUpgrade v8-11.3-develUpgrade nodejs20-develUpgrade nodejs20-libsUpgrade nodejs20-npmUpgrade nodejs20 | Feb 17, 2025 | Jul 10, 2024 |
| Debian | — | Upgrade nodejs | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | May 15, 2025 | Jul 10, 2024 |
| Oracle_linux | — | Upgrade nodejs-develUpgrade nodejs-full-i18nUpgrade nodejs-nodemonUpgrade nodejsUpgrade nodejs-docsUpgrade npmUpgrade nodejs-packaging-bundlerUpgrade nodejs-packaging | Oct 16, 2024 | Jul 10, 2024 |
| Redhat_linux | — | Upgrade nodejs-debuginfoUpgrade nodejs-packaging-bundlerUpgrade npmUpgrade nodejs-full-i18nUpgrade nodejsUpgrade nodejs-packagingUpgrade nodejs-develUpgrade nodejs-docsUpgrade nodejs-debugsourceUpgrade nodejs-nodemon | Sep 13, 2024 | Jul 10, 2024 |
| Rocky_linux | — | Upgrade nodejs-full-i18nUpgrade nodejs-debugsourceUpgrade nodejsUpgrade nodejs-develUpgrade npmUpgrade nodejs-debuginfo | Sep 17, 2024 | Jul 10, 2024 |
| Suse | — | Upgrade nodejs22-develUpgrade nodejs20-develUpgrade corepack20Upgrade corepack22Upgrade nodejs20Upgrade npm20Upgrade nodejs22Upgrade nodejs22-docsUpgrade npm22Upgrade nodejs20-docs | Jul 18, 2024 | Jul 10, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 10, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub