Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
Node.js 权限许可和访问控制问题漏洞
Vulnerability Description
Node.js是Node.js基金会开源的一个开源、跨平台的 JavaScript 运行时环境。 Node.js 22.x版本、24.x版本和26.x版本存在权限许可和访问控制问题漏洞,该漏洞源于权限模型执行缺陷,允许process.report在--allow-fs-write路径之外写入(和覆盖)文件,可能导致机密性影响或绕过预期安全边界。
CVSS Information
N/A
Vulnerability Type
N/A