CVE-2026-48617

Source
https://cve.org/CVERecord?id=CVE-2026-48617
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-48617.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-48617
Aliases
Downstream
Related
Published
2026-06-18T16:21:12Z
Modified
2026-08-21T05:06:12Z
Severity
  • 1.8 (Low) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A flaw in Node.js Permission Model enforcement allows Bypass via process.report.writeReport() Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

Database specific
{
    "cna_assigner": "hackerone",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48617.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "22.22.3"
                },
                {
                    "last_affected": "22.22.3"
                },
                {
                    "introduced": "24.16.0"
                },
                {
                    "last_affected": "24.16.0"
                },
                {
                    "introduced": "26.3.0"
                },
                {
                    "last_affected": "26.3.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/nodejs/node

Affected ranges

Type
GIT
Repo
https://github.com/nodejs/node
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*",
    "extracted_events": [
        {
            "introduced": "22.0.0"
        },
        {
            "last_affected": "22.22.3"
        },
        {
            "introduced": "24.0.0"
        },
        {
            "last_affected": "24.16.0"
        },
        {
            "introduced": "26.0.0"
        },
        {
            "last_affected": "26.3.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v22.*
v22.0.0
v22.1.0
v22.10.0
v22.11.0
v22.12.0
v22.13.0
v22.13.1
v22.14.0
v22.15.0
v22.15.1
v22.16.0
v22.17.0
v22.17.1
v22.18.0
v22.19.0
v22.2.0
v22.20.0
v22.21.0
v22.21.1
v22.22.0
v22.22.1
v22.22.2
v22.22.3
v22.3.0
v22.4.0
v22.4.1
v22.5.0
v22.5.1
v22.6.0
v22.7.0
v22.8.0
v22.9.0
v24.*
v24.0.0
v24.0.1
v24.0.2
v24.1.0
v24.10.0
v24.11.0
v24.11.1
v24.12.0
v24.13.0
v24.13.1
v24.14.0
v24.14.1
v24.15.0
v24.16.0
v24.2.0
v24.3.0
v24.4.0
v24.4.1
v24.5.0
v24.6.0
v24.7.0
v24.8.0
v24.9.0
v26.*
v26.0.0
v26.1.0
v26.2.0
v26.3.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-48617.json"