CVE-2026-48935
Analyzed Analyzed - Analysis Complete
Permission API File Metadata Modification in Node.js

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: HackerOne

Description
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-27
AI Q&A
2026-06-26
EPSS Evaluated
2026-06-26
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
nodejs node.js 26.3.0
nodejs node.js 24.16.0
nodejs node.js 22.22.3
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in the Node.js Permission API that allows modification of file metadata even on paths that are intended to be read-only, such as those specified with the --allow-fs-read flag.

Impact Analysis

The vulnerability can lead to unauthorized changes to file metadata on supposedly read-only paths, which may affect the integrity and expected behavior of files within applications using Node.js versions 22, 24, or 26.

Mitigation Strategies

To mitigate this vulnerability, users are advised to update Node.js to the latest patched versions of the affected release lines: Node.js 22, Node.js 24, and Node.js 26.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48935. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart