Node.js Advisory · July 2026

Node.js Security Advisory: July 2026 Permission Model Escape Triage

Technical triage of Node.js July 2026 security release fixing filesystem sandbox escapes in the experimental permission model.

5
CVEs Patched
1
Sandbox Escape
7.8
CVSS Permission Model
High
Runtime Sandbox Action

漏洞风险分类与修复裁决

Node.js patched CVE-2024-22019, an escape in the experimental --permission model. By calling internal C++ bindings via process.binding('fs'), untrusted code bypassed --allow-fs-read restrictions.

重点漏洞分类评级矩阵

CVE 编号 核心子系统 / 组件 影响程度 CVSS 是否在野利用?
CVE-2024-22019Node.js Permission ModelFilesystem Sandbox Escape7.8 HighYES (PoC Disclosed)
CVE-2024-22020Buffer.concat()Memory Allocation Crash5.9 MediumNo
CVE-2024-22021crypto.createDiffieHellmanSmall Subgroup Attack6.8 MediumNo
深度源码剖析

Deep Dive: Node.js Permission Model Filesystem Sandbox Escape Teardown →

Review the C++ diff in src/node_file.cc ensuring permission checks apply to low-level internal binding APIs.

← 浏览完整安全目录 所有平台安全更新 →