An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
2023-02-23T20:15:14.047
2025-03-17T19:15:19.303
Modified
CVSSv3.1: 4.2 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nodejs | node.js | ≤ 14.14.0 | Yes |
Application | nodejs | node.js | < 14.21.3 | Yes |
Application | nodejs | node.js | ≤ 16.12.0 | Yes |
Application | nodejs | node.js | < 16.19.1 | Yes |
Application | nodejs | node.js | ≤ 18.11.0 | Yes |
Application | nodejs | node.js | < 18.14.1 | Yes |
Application | nodejs | node.js | < 19.6.1 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |