A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
CVSS Details
- CVSS 3.0 Base Score: 2.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nodejsUpgrade nodejs-packagingUpgrade nodejs-full-i18nUpgrade nodejs-packaging-bundlerUpgrade npmUpgrade nodejs-nodemonUpgrade nodejs-docsUpgrade nodejs-devel | Aug 28, 2024 | Jul 10, 2024 |
| Alpine Linux | — | Upgrade nodejs | Aug 22, 2024 | Jul 10, 2024 |
| Amazon_linux_2023 | — | Upgrade nodejs20-debugsourceUpgrade nodejs20-full-i18nUpgrade nodejs20-develUpgrade nodejs20-debuginfoUpgrade nodejs20-libsUpgrade nodejs20Upgrade nodejs20-npmUpgrade nodejs20-docsUpgrade nodejs20-libs-debuginfoUpgrade v8-11.3-devel | Feb 17, 2025 | Jul 10, 2024 |
| Debian | — | Upgrade nodejs | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | May 15, 2025 | Jul 10, 2024 |
| Oracle_linux | — | Upgrade nodejs-packaging-bundlerUpgrade npmUpgrade nodejs-packagingUpgrade nodejs-full-i18nUpgrade nodejs-nodemonUpgrade nodejsUpgrade nodejs-docsUpgrade nodejs-devel | Oct 16, 2024 | Jul 10, 2024 |
| Redhat_linux | — | Upgrade nodejs-develUpgrade nodejs-nodemonUpgrade nodejs-docsUpgrade nodejs-debugsourceUpgrade nodejsUpgrade nodejs-packagingUpgrade nodejs-debuginfoUpgrade nodejs-full-i18nUpgrade nodejs-packaging-bundlerUpgrade npm | Sep 13, 2024 | Jul 10, 2024 |
| Rocky_linux | — | Upgrade nodejsUpgrade nodejs-debugsourceUpgrade nodejs-full-i18nUpgrade npmUpgrade nodejs-debuginfoUpgrade nodejs-devel | Sep 17, 2024 | Jul 10, 2024 |
| Suse | — | Upgrade nodejs20-docsUpgrade npm22Upgrade nodejs22-docsUpgrade npm20Upgrade nodejs22Upgrade corepack20Upgrade corepack22Upgrade nodejs20-develUpgrade nodejs22-develUpgrade nodejs20 | Jul 18, 2024 | Jul 10, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 10, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub