CVE-2026-21636Patch(nodejs / node.js)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nodejs node.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath options) can connect to arbitrary local sockets via net, tls, or undici/fetch. This breaks the intended security boundary of the permission model and enables access to privileged local services, potentially leading to privilege escalation, data exposure, or local code execution. * The issue affects users of the Node.js permission model on version v25. In the moment of this vulnerability, network permissions (`--allow-net`) are still in the experimental phase.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-13: 1Mentions · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-06: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-02-13: 1Technical Details · 2026-05-06: 102-1305-06
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-131
Patch1
2026-05-061
Disclosure1
Full discourse2 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: A critical vulnerability in #NodeJS allows attackers to bypass the permission model via Unix Domain Socket connections. #CVE-2026-21636 A #PoC is now available. #Patch #Patch #Patch More info: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases

    Post summary

    A critical Node.js vulnerability (CVE‑2026‑21636) that allows permission bypass via Unix Domain Sockets has been disclosed, PoC availability is announced, and patch details are provided by the vendor.

    01011285
    7.2K followersView on X
  • Mr Vibe Coder@MrVibeCoder
    Patch

    ⚠️ Critical Update: OpenClaw requires Node.js 22.12.0+ to patch CVE-2025-59466 (DoS) & CVE-2026-21636 (Permission bypass). If you're on older LTS, your gateway is vulnerable to identity exfiltration. Verify: node --version Fix: openclaw --update #OpenClaw #SecurityForces

    Post summary

    The post urges OpenClaw users to update Node.js to 22.12.0+ and run "openclaw --update" to patch the DoS and permission bypass CVEs listed.

    00000101
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more