CVE-2023-39331: Node.js

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Affected products

  • Node.js Node.js: from 20.0.0, before 20.8.1 (fixed in 20.8.1)

Published 2023-10-18. Last modified 2026-06-17.