Junglewise Threat Intelligence

CVE-2026-21711: Node.js Permission Model bypass in Unix Domain Socket operations

CVE-2026-21711 · Severity: medium · CVSS 5.3 · Published 2026-03-30

Executive brief

Node.js includes a Permission Model feature that restricts network and filesystem access to prevent untrusted code from causing harm. A flaw in this permission enforcement allows code running with the --permission flag (but without --allow-net) to create and expose local inter-process communication (IPC) endpoints, bypassing the intended network restrictions. An attacker with local access to a restricted Node.js process could communicate with it and potentially extract data or trigger harmful actions.

Technical details

Node.js Permission Model enforces network restrictions when --allow-net is omitted, but a gap exists in Unix Domain Socket (UDS) server operations (bind/listen). Unlike comparable network paths that correctly block UDS operations, the vulnerable code permits UDS servers to bind and listen without the required permission checks. The vulnerability affects only Node.js 25.x running with --permission without --allow-net (both experimental features). An attacker with local system access can communicate with exposed IPC endpoints to interact with the restricted process and circumvent the security boundary. Patches have been released in Node.js 25.x and backported to 24.x, 22.x, and 20.x versions.

Affected products

  • Node.js Node.js 25.x

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched: Patches released for Node.js 25.x, 24.x, 22.x, and 20.x

References