Junglewise Threat Intelligence

CVE-2026-56847: Node.js Permission Model bypass in trace_events module

CVE-2026-56847 · Severity: low · CVSS 3.3 · Published 2026-07-30

Executive brief

Node.js is a popular environment for running JavaScript applications. A security feature called the Permission Model, which is designed to restrict what files an application can write to, contains a flaw that allows trace logs to be saved to unauthorized locations. This could allow an attacker or a malicious script to bypass security boundaries and write data to restricted parts of the file system.

Technical details

A vulnerability in the Node.js Permission Model enforcement mechanism allows the `trace_events.createTracing().enable()` API to bypass filesystem write restrictions. When the experimental Permission Model is active, the `--allow-fs-write` flag is intended to restrict file write operations to specific paths; however, the tracing module fails to properly validate these boundaries when generating log files. An attacker with the ability to execute code within the Node.js process can exploit this to write trace data to arbitrary locations on the disk. This issue affects Node.js versions 22.x, 24.x, and 26.x, and has been addressed in versions 22.23.2, 24.18.1, and 26.5.1.

Affected products

  • Node.js Node.js 22.x, 24.x, 26.x

Timeline

  • 2026-07-29: patched: Security releases v22.23.2, v24.18.1, and v26.5.1 made available.
  • 2026-07-30: disclosed: CVE published to NVD.

References