Source: node-moment Version: 2.30.1+ds1-3 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-moment. CVE-2026-17495[0]: | moment is a JavaScript date library for parsing, validating, | manipulating, and formatting dates. In versions 2.29.2 through | 2.30.1, a specially crafted non-string object passed to | moment.locale() can bypass the locale-name path-traversal guard. The | guard assumes the input is a string, so an object whose match() | method satisfies the check while its toString() returns a traversal | path reaches an internal require() call with attacker-controlled | path segments. This is an incomplete fix for CVE-2022-24785 and | primarily affects npm (server-side) users that pass user-provided | input directly to moment.locale(). The issue is fixed in moment | 2.31.0, and users should upgrade to 2.31.0 or later. As a | workaround, validate that any user-supplied input is a string before | passing it to moment.locale(). If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-17495 https://www.cve.org/CVERecord?id=CVE-2026-17495 [1] https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw Please adjust the affected versions in the BTS as needed. Regards, Salvatore

