FlawAtlas
Search the atlas
CVE-2023-30583 High

CVE-2023-30583

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Exploit probability 0.7%
Published December 16, 2024
Required by Not available
Last source change April 3, 2025

02 / AFFECTED SOFTWARE

Affected packages

Bitnami node
Bitnami node-min

04 / EVIDENCE

Source records

Open Source Vulnerabilities BIT-node-min-2023-30583

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

View original source
Open Source Vulnerabilities BIT-node-2023-30583

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

View original source

05 / REFERENCES

Further evidence