CVE-2026-56847: Low severity OpenJS Node.js vulnerability
A flaw in Node.js Permission Model enforcement allows traceevents.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js 22.x, 24.x, and 26.x.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.18.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56847?
The severity of CVE-2026-56847 is categorized as low with a score of 3.3.
How do I fix CVE-2026-56847?
To mitigate CVE-2026-56847, ensure that Node.js is updated to the latest version which addresses this vulnerability.
What impact does CVE-2026-56847 have?
CVE-2026-56847 may lead to a confidentiality impact or bypass of the intended security boundary under affected configurations.
Which versions of Node.js are affected by CVE-2026-56847?
CVE-2026-56847 affects Node.js version 22.x.
What steps can I take to secure my application against CVE-2026-56847?
Securing your application against CVE-2026-56847 involves applying security patches and reviewing your application’s permission model for exposure.