A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
CVSS Details
- CVSS 3.0 Base Score: 2.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nodejs-full-i18nUpgrade nodejsUpgrade nodejs-packaging-bundlerUpgrade nodejs-packagingUpgrade nodejs-nodemonUpgrade nodejs-develUpgrade nodejs-docsUpgrade npm | Aug 28, 2024 | Jul 10, 2024 |
| Alpine Linux | — | Upgrade nodejs | Aug 22, 2024 | Jul 10, 2024 |
| Amazon_linux_2023 | — | Upgrade nodejs20-full-i18nUpgrade nodejs20-debugsourceUpgrade nodejs20-libsUpgrade nodejs20Upgrade nodejs20-debuginfoUpgrade v8-11.3-develUpgrade nodejs20-develUpgrade nodejs20-docsUpgrade nodejs20-npmUpgrade nodejs20-libs-debuginfo | Feb 17, 2025 | Jul 10, 2024 |
| Debian | — | Upgrade nodejs | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | May 15, 2025 | Jul 10, 2024 |
| Oracle_linux | — | Upgrade npmUpgrade nodejs-packaging-bundlerUpgrade nodejs-packagingUpgrade nodejs-nodemonUpgrade nodejs-full-i18nUpgrade nodejs-docsUpgrade nodejs-develUpgrade nodejs | Oct 16, 2024 | Jul 10, 2024 |
| Redhat_linux | — | Upgrade nodejsUpgrade npmUpgrade nodejs-packaging-bundlerUpgrade nodejs-debuginfoUpgrade nodejs-full-i18nUpgrade nodejs-packagingUpgrade nodejs-docsUpgrade nodejs-develUpgrade nodejs-nodemonUpgrade nodejs-debugsource | Sep 13, 2024 | Jul 10, 2024 |
| Rocky_linux | — | Upgrade nodejs-debugsourceUpgrade nodejsUpgrade nodejs-full-i18nUpgrade nodejs-develUpgrade npmUpgrade nodejs-debuginfo | Sep 17, 2024 | Jul 10, 2024 |
| Suse | — | Upgrade corepack20Upgrade corepack22Upgrade nodejs20-develUpgrade nodejs22-develUpgrade nodejs20Upgrade nodejs22Upgrade nodejs22-docsUpgrade nodejs20-docsUpgrade npm20Upgrade npm22 | Jul 18, 2024 | Jul 10, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 10, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub