Low severity3.3NVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026
CVE-2026-48936
CVE-2026-48936
Description
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the --allow-net permission.
This vulnerability affects one supported release line: Node.js 26.
Affected products
5- osv-coords3 versions
< 26.3.1-1.1+ 2 more
- (no CPE)range: < 26.3.1-1.1
- (no CPE)range: >= 26.3.0, < 26.3.1
- (no CPE)range: >= 26.3.0, < 26.3.1
Patches
Vulnerability mechanics
References
1- nodejs.org/en/blog/vulnerability/june-2026-security-releasesnvdPatchVendor Advisory
News mentions
1- Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication BypassesCyber Security News · Jun 19, 2026