CVE-2026-48617
Received Received - Intake
Permission Bypass in Node.js via process.report.writeReport

Publication date: 2026-06-18

Last updated on: 2026-06-18

Assigner: HackerOne

Description
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-18
Last Modified
2026-06-18
Generated
2026-06-19
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
nodejs node.js 22
nodejs node.js 24
nodejs node.js 26
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

This vulnerability can lead to a confidentiality impact or allow an attacker to bypass the intended security boundaries in affected Node.js environments. Although it is considered low severity, it could expose sensitive information or weaken security controls if exploited.

Mitigation Strategies

To mitigate this vulnerability, users are advised to update Node.js to the latest patched versions of the affected release lines: 22.x, 24.x, and 26.x.

Executive Summary

CVE-2026-48617 is a low-severity security vulnerability in Node.js that involves a flaw in the Permission Model enforcement. Specifically, it allows bypassing security restrictions via path misvalidation in the function process.report.writeReport(). This means that under certain configurations, an attacker could bypass intended security boundaries.

Compliance Impact

This vulnerability in Node.js allows bypassing the Permission Model via path misvalidation, which can lead to confidentiality impact or bypass of intended security boundaries under certain configurations.

Such confidentiality impacts could potentially affect compliance with standards and regulations like GDPR or HIPAA, which require protection of sensitive data and strict access controls.

However, the provided information does not explicitly detail the direct effects on compliance with these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48617. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart