A AegiFlow
HIGHCVSS 7.5

CVE-2023-38552

CVE-2023-38552 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

Affected packages

EcosystemPackageAffected versionsFixed versions
Node.jsnode.js[object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.