Medium · published July 30, 2026
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
| Product | Versions | Fixed in |
|---|---|---|
| nodejs/node.js | ≥ 22.0, ≤ 22.23.1 | — |
| nodejs/node.js | ≥ 24.0.0, ≤ 24.18.0 | — |
| nodejs/node.js | ≥ 26.0.0, ≤ 26.5.0 | — |