CVE-2026-58043

Aliases:ALPINE-CVE-2026-58043UBUNTU-CVE-2026-58043DEBIAN-CVE-2026-58043CGA-4f6v-xx87-m56gCGA-96qr-cj22-v3w7CGA-jm4p-q2gm-hh9cCGA-r3cw-xg7g-hc2qCGA-v98h-fx6m-mp68CGA-x5vj-cjrj-69xq
Analyzed
Published: 30 Jul 2026, 06:02
Last modified:31 Jul 2026, 03:55

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.4 HIGH
v3.1 (nvd)
EPSS Score
0.15% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2026, 06:02
Published
Vulnerability first disclosed
31 Jul 2026, 03:55
Last Modified
Vulnerability information updated

Description

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.

CVSS Metrics

  • v3.1HIGHScore: 8.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • v3.0HIGHScore: 7.5CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.15% Percentile: 4%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • alpinenodejs

    < 22.23.2-r0 | < 22.23.2-r0 | < 24.18.1-r0 | < 24.18.1-r0

  • chainguardnodejs-20

    all

  • chainguardnodejs-22

    < 22.23.2-r0

  • chainguardnodejs-25

    all

  • wolfinodejs-20

    all

  • wolfinodejs-22

    < 22.23.2-r0

  • wolfinodejs-25

    all

  • debiannodejs

    all | all | < 24.19.0+dfsg+~cs24.13.3-1

  • ubuntunodejs

    all | all | all

  • nodejsnode

    22.23.1 | 24.18.0 | 26.5.0

  • nodejsnode.js

    ≥ 22.0, ≤ 22.23.1 | ≥ 24.0.0, ≤ 24.18.0 | ≥ 26.0.0, ≤ 26.5.0

References (8)