Unrated severityOSV Advisory· Published Jan 20, 2026· Updated Jan 21, 2026
CVE-2026-21636
CVE-2026-21636
Description
A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when --permission is enabled. Even without --allow-net, attacker-controlled inputs (such as URLs or socketPath options) can connect to arbitrary local sockets via net, tls, or undici/fetch. This breaks the intended security boundary of the permission model and enables access to privileged local services, potentially leading to privilege escalation, data exposure, or local code execution.
- The issue affects users of the Node.js permission model on version v25.
In the moment of this vulnerability, network permissions (--allow-net) are still in the experimental phase.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.