FlawAtlas
Search the atlas
CVE-2024-22020 Not scored

CVE-2024-22020

A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

Exploit probability 1.1%
Published July 9, 2024
Required by Not available
Last source change June 24, 2026

03 / CONNECTIONS

Connected vulnerabilities

related ALSA-2024:5814
related ALSA-2024:5815
related ALSA-2024:6147
related ALSA-2024:6148
related CGA-5GCV-J397-8H99
related OPENSUSE-SU-2024:14214-1
related OPENSUSE-SU-2024:14435-1
related OPENSUSE-SU-2025:15802-1
related SUSE-SU-2024:2496-1
related SUSE-SU-2024:2542-1
related SUSE-SU-2024:2543-1
related SUSE-SU-2024:2574-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-22020

A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

View original source

05 / REFERENCES

Further evidence