CyberRota Analysis
AI-GeneratedA flaw in the Node.js Permission Model allows the `trace_events.createTracing().enable()` function to write trace logs outside of the intended `--allow-fs-write` boundary, potentially leading to confidentiality breaches. This issue primarily affects Node.js versions 22.x, 24.x, and 26.x, and should be prioritized by developers and system administrators using these versions in environments where sensitive data handling is critical.
Original NVD Description
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Related CVEs
Other vulnerabilities affecting the same vendor(s)