CVE-2023-32005

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/09/2023
Last modified:
05/05/2025

Description

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument.<br /> <br /> This flaw arises from an inadequate permission model that fails to restrict file stats through the `fs.statfs` API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.<br /> <br /> This vulnerability affects all users using the experimental permission model in Node.js 20.<br /> <br /> Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 20.0.0 (including) 20.5.1 (excluding)