Source: node-moment
Version: 2.30.1+ds1-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-moment.

CVE-2026-17495[0]:
| moment is a JavaScript date library for parsing, validating,
| manipulating, and formatting dates. In versions 2.29.2 through
| 2.30.1, a specially crafted non-string object passed to
| moment.locale() can bypass the locale-name path-traversal guard. The
| guard assumes the input is a string, so an object whose match()
| method satisfies the check while its toString() returns a traversal
| path reaches an internal require() call with attacker-controlled
| path segments. This is an incomplete fix for CVE-2022-24785 and
| primarily affects npm (server-side) users that pass user-provided
| input directly to moment.locale(). The issue is fixed in moment
| 2.31.0, and users should upgrade to 2.31.0 or later. As a
| workaround, validate that any user-supplied input is a string before
| passing it to moment.locale().


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-17495
    https://www.cve.org/CVERecord?id=CVE-2026-17495
[1] https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to