CVE-2026-58039

high

Description

A flaw in Node.js Permission Model enforcement allows process.report to write and overwrite files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. Impact: Thank you, to sinan-polat for reporting this vulnerability and thank you RafaelGSS for fixing it.

Details

Source: Mitre, NVD

Published: 2026-07-29

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High