CVE-2026-48617: High severity Node.js Node.js vulnerability
A flaw in Node.js Permission Model enforcement allows Bypass via process.report.writeReport() Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48617?
The severity of CVE-2026-48617 is low with a CVSS score of 1.8.
What impact does CVE-2026-48617 have?
CVE-2026-48617 can lead to a confidentiality impact or a bypass of the intended security boundary.
How does CVE-2026-48617 allow for a bypass?
CVE-2026-48617 allows for a bypass via process.report.writeReport() due to a flaw in Node.js Permission Model enforcement.
Which versions of Node.js are affected by CVE-2026-48617?
CVE-2026-48617 affects all supported release lines of Node.js 22 and later.
How can I mitigate CVE-2026-48617?
Mitigation for CVE-2026-48617 includes upgrading to a patched version of Node.js that addresses this vulnerability.