node is vulnerable to Improper Access Control
85
High Risk
Affected versions of the package allow a permissions bypass in the Node.js Permission Model, where filesystem path matching can over-grant access across radix-tree prefix boundaries. Under --permission, when multiple allowlisted paths share a common prefix, a radix-tree node split can incorrectly mark an intermediate prefix as granted. An attacker who is allowed access to one path can then read from or write to sibling paths outside the intended filesystem allowlist. The fix only preserves leaf grants on split nodes that were already end nodes.
You are affected if you are using a version that falls within the vulnerable range.
node is vulnerable to Improper Access Control in versions 25.0.0 - 26.5.0, 23.0.0 - 24.18.0 and 0.0.1 - 22.23.1.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant