logo

Database

Improper authorization control for web services In nodejs

Description

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read.

This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

1-10 of 11

10