node is vulnerable to Missing Authorization
25
Low Risk
Affected versions of the package allow a Permission Model bypass where trace_events.createTracing().enable() can write trace logs outside paths permitted by --allow-fs-write. Enabling tracing did not enforce filesystem write permission checks against the configured trace event file pattern, so code running under a restricted Permission Model could write outside the intended allowlist and weaken the security boundary. The fix checks FileSystemWrite permission on the resolved trace file path before starting the tracing agent.
You are affected if you are using a version that falls within the vulnerable range and run Node.js with the Permission Model enabled while using trace_events.
node is vulnerable to Missing Authorization in versions 25.0.0 - 26.5.0, 23.0.0 - 24.18.0 and 0.0.1 - 22.23.1.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant