CVE-2026-48935
EUVD-2026-3960826.06.2026, 02:16
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nodejs | node.js | 22.22.3 |
| nodejs | node.js | 24.16.0 |
| nodejs | node.js | 26.3.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| nodejs22 |
| ||||
| nodejs22-devel |
| ||||
| nodejs22-docs |
| ||||
| nodejs24 |
| ||||
| nodejs24-devel |
| ||||
| nodejs24-docs |
| ||||
| npm22 |
| ||||
| npm24 |
|
Common Weakness Enumeration
Vulnerability Media Exposure