Improper access control in Node.js - CVE-2026-58043
Published: July 29, 2026 / Updated: July 29, 2026
Node.js
Detailed vulnerability description
The vulnerability allows a local user to read from or write to paths outside the intended filesystem allowlist.
The vulnerability exists due to improper access control in Node.js Permission Model path matching when handling radix-tree prefix boundaries under --permission. A local user can abuse prefix boundary handling to read from or write to paths outside the intended filesystem allowlist.
The issue applies only when the Permission Model is enabled with --permission.