Improper access control in Node.js - CVE-2026-48617
Published: June 22, 2026
Node.js
Detailed vulnerability description
The vulnerability allows a local user to bypass the intended security boundary.
The vulnerability exists due to improper access control in process.report.writeReport() path validation when enforcing the permission model. A local user can provide a crafted path to bypass the intended security boundary.
This can lead to confidentiality impact under affected configurations.