CVE-2023-30584: Node.js Node

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass when verifying file permissions. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Affected products

  • Node.js Node: from 4.0, before 5 (fixed in 5); from 5.0, before 6 (fixed in 6); from 6.0, before 7 (fixed in 7); from 7.0, before 8 (fixed in 8); from 8.0, before 9 (fixed in 9); from 9.0, before 10 (fixed in 10); …
  • Node.js Node.js: from 20.0, before 20.3.1 (fixed in 20.3.1)

Published 2024-09-07. Last modified 2026-06-17.