CVE-2023-32004: Fedoraproject Fedora

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental permission model in Node.js 20. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Affected products

  • Fedoraproject Fedora: version 37 only; version 38 only
  • Node.js Node.js: from 20.0.0, up to and including 20.5.0

Published 2023-08-15. Last modified 2026-06-17.