CVE-2026-48617
NONE EPSS 11.0%
Published Jun 18, 20261w ago · Modified Jun 22, 20261w ago
Published Jun 18, 2026 1w ago
Last Modified Jun 22, 2026 1w ago
Description
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Threat Intelligence
EPSS Exploit Probability
11.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-284
References 2
- hackerone.com http://hackerone.com/reports/3692858
- nodejs.org https://nodejs.org/en/blog/vulnerability/june-2026-security-releases
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.