GHSA-4p3w-j4w9-5jqw: Path Traversal

Published Sep 29, 2026
·
Updated

Impact

moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.

This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.

Patches

This issue is patched in moment 2.31.0.

Workarounds

Validate that any user-supplied input is a string before passing it to moment.locale().

Affected Software

1 affected componentFixes available
npm/moment>=2.29.2<2.31.0
2.31.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/moment to a version that resolves this vulnerability.

    Fixed in 2.31.0
  2. Upgrade

    Upgrade moment to a version that resolves this vulnerability.

    Fixed in 2.31.0
  3. Compensating control

    Validate that any user-supplied input is a string before passing it to moment.locale().

Event History

Sep 29, 2026
Advisory Published
via GitHub·11:46 PM
Data Sourced
via GitHub·11:46 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Only server-side users of the npm package are affected. The issue applies to moment versions earlier than 2.31.0 when attacker-influenced values can reach moment.locale().

2

What input is required to exploit this issue?

An attacker must be able to supply a non-string value to moment.locale(). Plain string input is not affected because locale names containing path separators are rejected by the existing validation.

3

What can be done if upgrading is not immediately possible?

Validate that all user-supplied input is a string before passing it to moment.locale(). This prevents the crafted-object validation bypass described in the advisory.

4

How can I determine whether my application is exposed?

Review server-side code paths that call moment.locale() and determine whether they can receive attacker-influenced non-string values, such as objects. Applications that pass only validated strings to this function are not affected by this bypass.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203