PT-2026-3317 · Node.Js · Node.Js

Mufeedvh

·

Published

2026-01-13

·

Updated

2026-05-06

·

CVE-2026-21636

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js version 25
Description A flaw in the permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when --permission is enabled. Even without --allow-net, attacker-controlled inputs, such as URLs or socketPath options, can connect to arbitrary local sockets via net, tls, or undici/fetch. This breaks the intended security boundary of the permission model and enables access to privileged local services, potentially leading to privilege escalation, data exposure, or local code execution. The network permissions (--allow-net) are currently in the experimental phase.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2026-01353
BIT-NODE-2026-21636
BIT-NODE-MIN-2026-21636
CVE-2026-21636
RHSA-2026:6402
RHSA-2026:6431
RHSA-2026:7386
RHSA-2026:7387

Affected Products

Node.Js