CVE-2026-21715Patch(nodejs / node.js)

LOWCVSS 3.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-03-24); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-31: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 103-2403-2503-3003-3104-0904-11
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-242
Patch2
2026-03-251
Patch1
2026-03-301
Patch1
2026-03-312
Disclosure2
2026-04-091
Patch1
2026-04-111
Patch1
Full discourse8 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 モジュール更新情報 22.22.2-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nodejs 22.22.2-1 この更新には脆弱性(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714, CVE-2026-21717, CVE-2026-21715, CVE-202... https://kusanagi.tokyo/releases/23908/

    Post summary

    The KUSANAGI 9 release updates the nodejs module to 22.22.2‑1, addressing multiple CVE‑2026 vulnerabilities and providing a patch for the identified weaknesses.

    01020120
    200 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    Additionally, the update tackles CVE-2026-21710 by using null prototypes for headersDistinct/trailersDistinct in the http module, and CVE-2026-21716 and CVE-2026-21715, which add necessary permission checks to lib/fs/promises and realpath.native, 3/6

    Post summary

    An update patches CVE-2026-21710, CVE-2026-21716, and CVE-2026-21715 by applying null prototype fixes to the http module and adding permission checks to lib/fs/promises and realpath.native.

    1000028
    17 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    @rafaelgss Lower severity issues were also patched, including permission checks on lib/fs/promises (CVE-2026-21716) and realpath.native (CVE-2026-21715), both contributed by RafaelGSS. 9/17

    Post summary

    The tweet announces that lower‑severity vulnerabilities CVE‑2026‑21716 and CVE‑2026‑21715, affecting permission checks in lib/fs/promises and realpath.native, have been patched.

    1000023
    17 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21715 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesyst… https://www.cve.org/CVERecord?id=CVE-2026-21715

    Post summary

    The post states a Node.js permission model vulnerability affecting fs.realpathSync.native, but offers no PoC, exploit code, or patch details.

    00010200
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21715 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesyst… https://www.cve.org/CVERecord?id=CVE-2026-21715 ----- Traducción: CVE-2026-21715 Un … http://infoflow.cloud`

    Post summary

    This brief notice announces the Node.js vulnerability CVE-2026-21715, detailing a permission-check flaw in fs.realpathSync.native(), but does not include a PoC, exploit, patch, or proof of active exploitation.

    0000022
    65 followersView on X
  • ティー🌐@TeeTheta
    Patch

    対処された脆弱性(22.x対象8件) CVE-2026-21637 (High) CVE-2026-21710 (High) CVE-2026-21713 (Medium) CVE-2026-21714 (Medium) CVE-2026-21717 (Medium) CVE-2026-21715 (Low) CVE-2026-21716 (Low) undici 6.24.1/7.24.4 への依存更新

    Post summary

    A set of eight CVEs has been addressed by updating the undici library to versions 6.24.1 and 7.24.4.

    0000071
    1 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v24.14.1 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリースです。 • undiciを7.24.4に更新 • npmを11.11.0にアップグレード • V8の依存関係を更新 🔧 重要な修正: • (CVE-2026-21710) headersDistinct/trailersDistinctにnullプロトタイプを使用 • (CVE-2026-21637) SNICallback呼び出しをtry/catchでラップ • (CVE-2026-21717) 配列インデックスのハッシュ衝突をテスト • (CVE-2026-21713) Web Cryptography HMACおよびKMACでタイミング安全な比較を使用 • (CVE-2026-21714) NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 • (CVE-2026-21712) 異なるURL形式でのURLクラッシュを処理 • (CVE-2026-21716) lib/fs/promisesにパーミッションチェックを含める • (CVE-2026-21715) realpath.nativeにパーミッションチェックを追加 #GitHub #Release #Node.js

    Post summary

    Node.js v24.14.1 is a security patch release that addresses several CVEs; it includes detailed technical fixes for various vulnerabilities.

    0000066
    2 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    Node.js v25.8.2 release includes patches for multiple CVEs with detailed technical fixes.

    0000049
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more