B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

CVE-2026-49982 - tmp: Type-confusion bypass of _assertPath in [email protected] allows path traversal via non-string prefix/postfix/template

CVE ID :CVE-2026-49982 Published : June 11, 2026, 5:16 p.m. | 1 hour, 48 minutes ago Description :tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when...

Original-Artikel öffnen Zurück zur Übersicht