Back

HIGH

nodejs: permission model improperly protects against path traversal

Published Oct 18, 2023

Description

A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations.

Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Oct 18, 2023
Updated Nov 3, 2025
Reserved Jul 28, 2023
CISA Vulnrichment
Updated Sep 13, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 13, 2023