CVE-2023-23920: Debian Linux

Medium severity, CVSS 4.2. EPSS: 0.4% chance of exploitation in the next 30 days.

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Node.js Node.js: from 14.0.0, up to and including 14.14.0; from 14.0.0, before 14.21.3 (fixed in 14.21.3); from 16.0.0, up to and including 16.12.0; from 16.0.0, before 16.19.1 (fixed in 16.19.1); from 18.0.0, up to and including 18.11.0; from 18.0.0, before 18.14.1 (fixed in 18.14.1); …

Published 2023-02-23. Last modified 2026-06-17.