CVE-2023-30581: Node.js

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definition. This vulnerability affects all users using the experimental policy mechanism in all active release lines: v16, v18 and, v20. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js

Affected products

  • Node.js Node.js: from 16.0.0, before 16.20.1 (fixed in 16.20.1); from 18.0.0, before 18.16.1 (fixed in 18.16.1); from 20.0.0, before 20.3.1 (fixed in 20.3.1)

Published 2023-11-23. Last modified 2026-06-17.