PT-2026-29099 · Node.Js+1 · Node.Js+1

Xavlimsg

·

Publicado

2026-03-30

·

Atualizado

2026-04-13

·

CVE-2026-21711

CVSS v3.1

5.3

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Node.js versions 25.x
Description A flaw in the Node.js Permission Model’s network enforcement allows Unix Domain Socket (UDS) server operations to proceed without the necessary permission checks. All other network paths correctly enforce these checks. Consequently, code running under --permission without --allow-net can create and expose local Inter-Process Communication (IPC) endpoints, enabling communication with other processes on the same host, bypassing the intended network restriction boundary. The --allow-net feature is currently experimental.
Recommendations For Node.js version 25.x, avoid running processes under --permission without including the --allow-net flag to restrict network access.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:7350
ALSA-2026:7670
ALSA-2026:7675
BIT-NODE-2026-21711
BIT-NODE-MIN-2026-21711
CVE-2026-21711
RHSA-2026:7350
RHSA-2026:7670
RHSA-2026:7675

Produtos afetados

Node.Js
Rocky Linux