Npm · Moment · CVE-2026-17495
**Name of the Vulnerable Software and Affected Versions**
moment versions 2.29.2 through 2.30.1
**Description**
A path-traversal issue exists when a specially crafted non-string object is passed to the `moment.locale()` function. The internal guard assumes the input is a string; however, an object with a `match()` method that satisfies the check and a `toString()` method that returns a traversal path can reach an internal `require()` call with attacker-controlled path segments. This primarily affects server-side npm users who pass user-provided input directly to the function.
**Recommendations**
Update to version 2.31.0 or later.
As a temporary workaround, validate that any user-supplied input is a string before passing it to the `moment.locale()` function.