A flaw in Node.js Permission Model enforcement allows...
Low severity
Unreviewed
Published
Jul 31, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 31, 2026
Published to the GitHub Advisory Database
Jul 31, 2026
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js 22.x, 24.x, and 26.x.
References