CVE-2026-21715

Aliases:DEBIAN-CVE-2026-21715ALPINE-CVE-2026-21715CGA-2vfv-qrv3-gp35CGA-72w7-x4mh-3wc2CGA-9xh5-2p35-crrjCGA-fxmm-vjg4-gcwcCGA-m869-7qjq-5q5qCGA-m897-fgw5-6mg5CGA-qxmm-jm3g-xwfjCGA-v8rp-5qr4-hpr7CGA-wrmw-vch4-gg24CGA-xxvv-p446-6g6g
Analyzed
Published: 30 Mar 2026, 19:07
Last modified:17 Sept 2026, 18:36

Vulnerability Summary

Overall Risk (default)
low
13/100
CVSS Score
3.3 LOW
v3.0 (cve.org)
EPSS Score
0.16% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Mar 2026, 19:07
Published
Vulnerability first disclosed
17 Sept 2026, 18:36
Last Modified
Vulnerability information updated

Description

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.

CVSS Metrics

  • v3.0LOWScore: 3.3CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS Trends

Current EPSS score: 0.16% Percentile: 5%

Techniques & Countermeasures

  • CWE-732Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Affected Systems

  • alpinenodejs

    < 22.22.2-r0 | < 22.22.2-r0 | < 24.14.1-r0 | < 24.14.1-r0

  • chainguardnodejs-16

    all

  • chainguardnodejs-18

    all

  • chainguardnodejs-21

    all

  • chainguardnodejs-22

    < 22.22.3-r0

  • chainguardnodejs-23

    all

  • wolfinodejs-16

    all

  • wolfinodejs-18

    all

  • wolfinodejs-21

    all

  • wolfinodejs-22

    < 22.22.3-r0

  • wolfinodejs-23

    all

  • debiannodejs

    < 20.19.2+dfsg-1+deb13u2 | < 22.22.2+dfsg+~cs22.19.15-1

  • nodejsnode

    20.20.1 | 22.22.1 | 24.14.0 | 25.8.1 | ≥ 4.0, < 4.* | ≥ 5.0, < 5.* | ≥ 6.0, < 6.* | ≥ 7.0, < 7.* | ≥ 8.0, < 8.* | ≥ 9.0, < 9.* | ≥ 10.0, < 10.* | ≥ 11.0, < 11.* | ≥ 12.0, < 12.* | ≥ 13.0, < 13.* | ≥ 14.0, < 14.* | ≥ 15.0, < 15.* | ≥ 16.0, < 16.* | ≥ 17.0, < 17.* | ≥ 18.0, < 18.* | ≥ 19.0, < 19.*

  • nodejsnode.js

    ≤ 20.20.1 | ≥ 22.0.0, ≤ 22.22.1 | ≥ 24.0.0, ≤ 24.14.0 | ≥ 25.0.0, ≤ 25.8.1

References (5)