Directory Traversal The advisory has been revoked - it doesn't affect any version of package nodejs:20/npm  (opens in a new tab)


Threat Intelligence

EPSS
1.24% (66th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL9-NODEJS-9501438
  • published21 Mar 2025
  • disclosed19 Feb 2024

Introduced: 19 Feb 2024

CVE-2024-21891  (opens in a new tab)
CWE-22  (opens in a new tab)

Amendment

The Red Hat security team deemed this advisory irrelevant for RHEL:9.

NVD Description

Note: Versions mentioned in the description apply only to the upstream nodejs:20/npm package and not the nodejs:20/npm package as distributed by RHEL.

Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.