PT-2026-66407 · Node.Js · Node
CVE-2026-56847
·
Publicado
2026-07-30
·
Atualizado
2026-07-30
CVSS v3.1
3.3
Baixa
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
A flaw in Node.js Permission Model enforcement allows
trace events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write.This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js 22.x, 24.x, and 26.x.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Node