CVE-2026-48617 - CERT CVE
ID CVE-2026-48617
Sažetak A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Reference
CVSS
Base: 1.8
Impact: 1.4
Exploitability:0.3
Pristup
VektorSloženostAutentikacija
LOCAL HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW NONE
CVSS vektor CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
Zadnje važnije ažuriranje 18-06-2026 - 19:16
Objavljeno 18-06-2026 - 17:16