← Back

CVE-2026-21715

nvd nist
Published: Mar 30, 2026Modified: Aug 19, 2026

JSON object

Loading...
3.3
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: support@hackerone.com (Secondary)

Description

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.

Affected (4)

Products: Nodejs: Node.js
1 product
Node.js
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
Up to 20.20.1
From 22.0.0 to 22.22.1
From 24.0.0 to 24.14.0
From 25.0.0 to 25.8.1

References (1)

Timeline

No history available yet.