CVE-2026-48936: Low severity npm/node vulnerability
Published Jun 26, 2026
·Updated
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the --allow-net permission. This vulnerability affects one supported release line: Node.js 26.
Affected Software
2 affected components
npm/node=26
Nodejs Node.js=26.3.0
Remediation
Event History
Jun 26, 2026
CVE Published
via MITRE·01:14 AM
Data Sourced
via MITRE·01:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48936?
The severity of CVE-2026-48936 is classified as low, with a score of 3.3.
2
How do I fix CVE-2026-48936?
To fix CVE-2026-48936, apply the available patch provided in the Node.js security releases.
3
What does CVE-2026-48936 affect?
CVE-2026-48936 affects the Node.js Permission API in Node.js version 26.
4
What is the impact of CVE-2026-48936?
CVE-2026-48936 can allow a local server to be started via a Unix domain socket without the necessary permissions.
5
When was CVE-2026-48936 published?
CVE-2026-48936 was published on June 26, 2026.