CVE-2026-56847: Node.js
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Affected products
- Node.js Node.js: from 22.0, up to and including 22.23.1; from 24.0.0, up to and including 24.18.0; from 26.0.0, up to and including 26.5.0
Published 2026-07-30. Last modified 2026-08-25.