CVE-2026-58039
published 2026-07-31CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to…
PriorityP412low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.15%
4.5th percentile
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nodejs | node | 22.23.1 – 22.23.1 | — |
| nodejs | node | 24.18.0 – 24.18.0 | — |
| nodejs | node | 26.5.0 – 26.5.0 | — |
| nodejs_22 | nodejs | — | — |
| nodejs_24 | nodejs | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
nodejs Node.js up to 22.23.1/24.18.0/26.5.0 Permission Model permission
vuldb·2026-07-31·CVSS 3.3
CVE-2026-58039 [LOW] nodejs Node.js up to 22.23.1/24.18.0/26.5.0 Permission Model permission
A vulnerability was found in nodejs Node.js up to 22.23.1/24.18.0/26.5.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Permission Model. The manipulation results in permission issues.
This vulnerability was named CVE-2026-58039. The attack may be performed from remote. There is no available exploit.
GHSA
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
ghsa_unreviewed·2026-07-31
CVE-2026-58039 [LOW] CWE-284 A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Red Hat
nodejs: Information disclosure due to improper permission enforcement
vendor_redhat·2026-07-31·CVSS 3.3
CVE-2026-58039 [LOW] CWE-73 nodejs: Information disclosure due to improper permission enforcement
nodejs: Information disclosure due to improper permission enforcement
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
A flaw was found in Node.js. The permission model enforcement, specifically related to `process.report` functionality, allows an attacker to write or overwrite files in locations outside of the intended secure paths. This vulnerability can lead to the disclosure of sensitive information or bypass the security boundaries designed to protect the system.
Statement: This flaw allows a local user with execution pr
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58039 nodejs22: Information disclosure due to improper permission enforcement [fedora-all]
bugzilla·2026-08-07·CVSS 3.3
CVE-2026-58039 [LOW] CVE-2026-58039 nodejs22: Information disclosure due to improper permission enforcement [fedora-all]
CVE-2026-58039 nodejs22: Information disclosure due to improper permission enforcement [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Bugzilla
CVE-2026-58039 nodejs24: Information disclosure due to improper permission enforcement [fedora-all]
bugzilla·2026-08-07·CVSS 3.3
CVE-2026-58039 [LOW] CVE-2026-58039 nodejs24: Information disclosure due to improper permission enforcement [fedora-all]
CVE-2026-58039 nodejs24: Information disclosure due to improper permission enforcement [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Bugzilla
CVE-2026-58039 nodejs: Information disclosure due to improper permission enforcement
bugzilla·2026-07-31·CVSS 3.3
CVE-2026-58039 [LOW] CVE-2026-58039 nodejs: Information disclosure due to improper permission enforcement
CVE-2026-58039 nodejs: Information disclosure due to improper permission enforcement
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
2026-07-31
Published