Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
Node.js 权限许可和访问控制问题漏洞
Vulnerability Description
Node.js是Node.js基金会开源的一个开源、跨平台的 JavaScript 运行时环境。 Node.js 22.22.3及之前版本、24.16.0及之前版本和26.3.0及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于权限模型强制实施缺陷,通过`process.report.writeReport()`路径验证错误可绕过安全边界,可能导致保密性影响。
CVSS Information
N/A
Vulnerability Type
N/A