What is CVE-2026-58039?
A flaw in the Node.js Permission Model enforcement allows the process.report to write and overwrite files outside the paths permitted by --allow-fs-write. This can lead to a confidentiality impact or a bypass of the intended security boundary under specific configurations, affecting Node.js versions 22.x and 24.x.
Azərbaycanca: Node.js İcazə Modelində (Permission Model) aşkarlanan qüsur tətbiqə `--allow-fs-write` ilə icazə verilən qovluqlardan kənarda `process.report` vasitəsilə fayl yazmağa (və üzərinə yazmağa) imkan verir. Bu, xüsusilə konfiqurasiyadan asılı olaraq məxfilik pozuntusuna (confidentiality impact) və ya nəzərdə tutulan təhlükəsizlik sərhədlərinin (security boundary) keçilməsinə səbəb ola bilər. Node.js 22.x və 24.x versiyalarını istifadə edən istifadəçilərə dərhal yeniləmə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which Node.js versions are affected by CVE-2026-58039?
Node.js versions 22.x and 24.x.
What security impacts can result from this vulnerability?
A confidentiality impact or a bypass of the intended security boundary.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.