
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2024-22018) has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. The vulnerability impacts Node.js versions 20 and 22, specifically in their experimental permission model feature. This security issue was discovered and reported by haxatron1, with fixes implemented by RafaelGSS (NodeJS Blog).
The vulnerability stems from an inadequate permission model that fails to restrict file stats through the fs.lstat API. The issue has been assigned a CVSS v3.0 score of 2.9 (LOW) with a vector string of CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N (HackerOne).
When exploited, malicious actors can retrieve stats from files that they do not have explicit read access to. This affects users who are specifically using the experimental permission model with the --allow-fs-read flag in Node.js versions 20 and 22 (NodeJS Blog).
The vulnerability requires local access and has high attack complexity, as indicated by the CVSS vector. It affects the experimental permission model feature, which was not yet finalized at the time of the CVE issuance (NodeJS Blog).
Updates have been released to address this vulnerability in Node.js versions 20.15.1 and 22.4.1. Users are advised to upgrade to these patched versions to mitigate the security risk (NodeJS Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."