CVE-2026-56847CWE-1119

CVE-2026-56847

Medium · published July 30, 2026

CVSS v3.1
6.1
EPSS
0%
Percentile
5.2
In the wild
Unconfirmed
What it is

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`.

This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.

This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

The record
Technical detail
CVSS v3.1
6.1 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00158 · 5.2th percentile
Weakness
CWE-1119 · Excessive Use of Unconditional Branching
Published
2026-07-30T10:25Z
Affected products (3)
ProductVersionsFixed in
nodejs/node.js≥ 22.0, ≤ 22.23.1
nodejs/node.js≥ 24.0.0, ≤ 24.18.0
nodejs/node.js≥ 26.0.0, ≤ 26.5.0
References (1)
EPSS history
Timeline
  • 30 JUL 06:02Z
    A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`
    cvelistv5