6.1mediumMedium

CVE-2026-56847

Nodejs Node.Js

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
6.1 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Weakness
CWE-1119
Assigned by
support@hackerone.com

Dates

Published
2026-07-30
Last modified
2026-08-25
Sources
NVD

Affected products

  • Nodejs Node.Js22.0 - 22.23.1, 24.0.0 - 24.18.0, 26.0.0 - 26.5.0

As listed in the NVD configuration data. Not a statement about your estate.

References