← לוח פגיעויות

CVE-2026-48935

טרם דורגה

טרם דורג — בהתאם למדיניות NVD מאפריל 2026, רוב ה-CVE אינם מנותחים מיידית. ציון EPSS (אם קיים) עדיין מוצג.

תיאור (מקור, אנגלית)

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

מדדים

EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-14/8/2026
CWE
CWE-276

מוצרים מושפעים

nodejs: node.js

קישורים