Moment.js < 2.29.2 Path Traversal

high Web App Scanning Plugin ID 115564

Synopsis

Moment.js < 2.29.2 Path Traversal

Description

According to its self-reported version number, Moment.js is prior to 2.29.2. Therefore, it may be affected by a path traversal vulnerability in the moment.locale() function. When a user-provided locale string is directly used to switch the moment locale, an attacker can craft a locale name containing path traversal sequences to load a file outside of the intended directory. Only server-side (npm) usage is affected. (CVE-2022-24785)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Moment.js version 2.29.2 or later.

See Also

https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4

Plugin Details

Severity: High

ID: 115564

Type: Version Based

Published: 10/2/2026

Updated: 10/2/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 96.65

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2022-24785

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS Score Source: CVE-2022-24785

Vulnerability Information

CPE: cpe:2.3:a:moment_project:moment:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 4/3/2022

Reference Information

CVE: CVE-2022-24785