Junglewise Threat Intelligence

CVE-2026-21716: Node.js FileHandle.chmod() and FileHandle.chown() permission bypass

CVE-2026-21716 · Severity: low · CVSS 3.3 · Published 2026-03-30

Vendors: OpenJS Foundation.

Executive brief

Node.js's permission model, designed to restrict what code can access when run with `--permission` flags, has an incomplete fix that leaves promise-based file operations vulnerable. Attackers can use FileHandle.chmod() and FileHandle.chown() in the promises API to change file permissions and ownership even when `--allow-fs-write` restrictions should prevent it, allowing privilege escalation or file tampering on systems relying on the permission model for security.

Technical details

This vulnerability is an incomplete fix for CVE-2024-36137. The callback-based equivalents fs.fchmod() and fs.fchown() were correctly patched to enforce permission checks, but their promise-based counterparts (FileHandle.chmod() and FileHandle.chown() in the promises API) lack the required permission validation. The attack vector is local and requires code to already be running under the --permission model with restricted --allow-fs-write settings; the attacker then invokes the vulnerable promise-based methods on open file descriptors to modify file metadata in violation of the intended restrictions. The impact is limited to systems explicitly using Node.js's experimental Permission Model feature. Patches are available in Node.js 20.x, 22.x, 24.x, and 25.x maintenance releases.

Affected products

  • OpenJS Foundation Node.js 20.x, 22.x, 24.x, 25.x

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched

References