Junglewise Threat Intelligence

CVE-2026-48936: Node.js Permission API network restriction bypass via Unix domain socket

CVE-2026-48936 · Severity: low · CVSS 3.3 · Published 2026-06-26

Executive brief

Node.js is a popular runtime environment used to build and run server-side applications. A security flaw in its Permission API allows a local user to start a server using Unix domain sockets even when network access is explicitly restricted. This could allow an attacker to bypass security policies intended to isolate the application from the local network environment.

Technical details

A vulnerability exists in the Node.js Permission API where the enforcement of network restrictions is incomplete. Specifically, an attacker with local access can initiate a server using a Unix domain socket, bypassing the security boundaries intended by the '--allow-net' flag. This issue is an incomplete fix for a previous vulnerability (CVE-2026-21636). The flaw is categorized as improper access control (CWE-284) and is addressed in Node.js version 26.3.1.

Affected products

  • Node.js Node.js 26.x before 26.3.1

Timeline

  • 2026-06-18: patched: Security releases available for 26.x, 24.x, and 22.x lines.
  • 2026-06-26: disclosed: NVD publication date.

References