Loading HuntDB...

GHSA-q793-mj5v-wh68

GitHub Security Advisory

⚠ Unreviewed LOW Has CVE

Advisory Details

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used.

Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

Related CVEs

Key Information

GHSA ID
GHSA-q793-mj5v-wh68
Published
September 7, 2024 6:30 PM
Last Modified
November 22, 2024 12:39 PM
CVSS Score
2.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.