VYPR

Node.js Permission Model

by Node.js

Source repositories

CVEs (1)

  • CVE-2026-58043HigJul 30, 2026
    risk 0.55cvss 8.4epss 0.00

    A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem…