node is vulnerable to Improper Access Control
30
Low Risk
Affected versions of the package allow improper enforcement of file system permissions in the Node.js permission model, where futimes() can be used to modify file access and modification timestamps even when the process has only read permissions. Unlike utimes(), futimes() does not apply the expected write-permission checks, enabling metadata changes in read-only directories and potentially allowing attackers to obscure activity and undermine the reliability of logs.
You are affected if you are using a version that falls within the vulnerable range.
node is vulnerable to Improper Access Control in versions 25.0.0 - 25.2.0, 23.0.0 - 24.12.0, 21.0.0 - 22.21.1 and 0.0.1 - 20.19.6.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant