A AegiFlow
MEDIUMCVSS 6.1

CVE-2026-56847

CVE-2026-56847 updated by NVD

Modified
2026-08-26
Sources
nvd

Summary

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Affected packages

EcosystemPackageAffected versionsFixed versions
Node.jsnode.js[object Object], [object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.