Improper access control in Node.js - CVE-2026-48617
Published: June 22, 2026
Vulnerability details
The vulnerability allows a local user to bypass the intended security boundary.
The vulnerability exists due to improper access control in process.report.writeReport() path validation when enforcing the permission model. A local user can provide a crafted path to bypass the intended security boundary.
This can lead to confidentiality impact under affected configurations.
Affected software
Anolis OS
nodejs-npm
v8-12.4-devel
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-libs
nodejs-docs
How to mitigate CVE-2026-48617
nodejs-npm - update to 10.9.8-1.22.23.0.1
v8-12.4-devel - update to 12.4.254.21-1.22.23.0.1
nodejs - update to 22.23.0-1
nodejs-devel - update to 22.23.0-1
nodejs-full-i18n - update to 22.23.0-1
nodejs-libs - update to 22.23.0-1
nodejs-docs - update to 22.23.0-1