CVE-2026-58043
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
30/07/2026
Última modificación:
30/07/2026
Descripción
*** Pendiente de traducción *** A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.<br />
<br />
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.<br />
<br />
This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA



