CVE-2026-48617
published 2026-06-18CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or…
PriorityP349high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.32%
24.2th percentile
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nodejs | node | 22.22.3 – 22.22.3 | — |
| nodejs | node | 24.16.0 – 24.16.0 | — |
| nodejs | node | 26.3.0 – 26.3.0 | — |
| nodejs | node.js | 22.0.0 – 22.22.3 | — |
| nodejs | node.js | 24.0.0 – 24.16.0 | — |
| nodejs | node.js | 26.0.0 – 26.3.0 | — |
| nodejs_22 | nodejs | — | — |
| nodejs_24 | nodejs | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv3.01.8LOWCVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
vendor_redhat1.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Node.js up to 22.22.3/24.16.0/26.3.0 Configuration process.report.writeReport access control (EUVD-2026-37914)
vuldb·2026-06-18
CVE-2026-48617 [LOW] Node.js up to 22.22.3/24.16.0/26.3.0 Configuration process.report.writeReport access control (EUVD-2026-37914)
A vulnerability was found in Node.js up to 22.22.3/24.16.0/26.3.0. It has been rated as critical. Affected is the function process.report.writeReport of the component Configuration Handler. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2026-48617. An attack has to be approached locally. There is no exploit available.
GHSA
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation.
ghsa_unreviewed·2026-06-18
CVE-2026-48617 [LOW] CWE-284 A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation.
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Red Hat
nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation
vendor_redhat·2026-06-18·CVSS 1.8
CVE-2026-48617 [LOW] CWE-73 nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation
nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw was found in Node.js. This vulnerability allows a bypass of the Permission Model enforcement due to path misvalidation within the `process.report.writeReport()` function. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access to sensitive information or other confidentiality impacts under specific
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-48617 nodejs20: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
bugzilla·2026-08-05·CVSS 1.8
CVE-2026-48617 [LOW] CVE-2026-48617 nodejs20: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
CVE-2026-48617 nodejs20: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Bugzilla
CVE-2026-48617 nodejs22: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
bugzilla·2026-08-05·CVSS 1.8
CVE-2026-48617 [LOW] CVE-2026-48617 nodejs22: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
CVE-2026-48617 nodejs22: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Bugzilla
CVE-2026-48617 nodejs24: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
bugzilla·2026-08-05·CVSS 1.8
CVE-2026-48617 [LOW] CVE-2026-48617 nodejs24: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
CVE-2026-48617 nodejs24: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Bugzilla
CVE-2026-48617 nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation
bugzilla·2026-06-18·CVSS 1.8
CVE-2026-48617 [LOW] CVE-2026-48617 nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation
CVE-2026-48617 nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
2026-06-18
Published