CVE-2024-36137

Severity
3.3LOW
EPSS
0.1%
top 75.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 7
Latest updateMar 30

Description

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5nodejs/node4.04.*+21
Alpinenodejs< 20.15.1-r0+4
Debiannodejs< 20.15.1+dfsg-1+1

🔴Vulnerability Details

4
GHSA
GHSA-q793-mj5v-wh68: A vulnerability has been identified in Node2024-09-07
CVEList
CVE-2024-36137: A vulnerability has been identified in Node2024-09-07
OSV
CVE-2024-36137: A vulnerability has been identified in Node2024-09-07
OSV
CVE-2024-36137: A vulnerability has been identified in Node2024-09-07

📋Vendor Advisories

3
Red Hat
nodejs: Node.js: Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.2026-03-30
Red Hat
nodejs: fs.fchown/fchmod bypasses permission model2024-07-08
Debian
CVE-2024-36137: nodejs - A vulnerability has been identified in Node.js, affecting users of the experimen...2024

💬Community

2
Bugzilla
CVE-2026-21716 nodejs: Node.js: Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.2026-03-30
HackerOne
fs.fchown/fchmod bypasses permission model2024-10-16
CVE-2024-36137 (LOW CVSS 3.3) | A vulnerability has been identified | cvebase.io