Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Gilmoreorless

#47946of 57,545
5.9Total CVSS
Vulnerabilities · 1
PT-2026-91861
5.9
2026-09-15
Npm · Moment · CVE-2026-17495
**Name of the Vulnerable Software and Affected Versions** moment versions 2.29.2 through 2.30.1 **Description** A path-traversal issue exists when a specially crafted non-string object is passed to the `moment.locale()` function. The internal guard assumes the input is a string; however, an object with a `match()` method that satisfies the check and a `toString()` method that returns a traversal path can reach an internal `require()` call with attacker-controlled path segments. This primarily affects server-side npm users who pass user-provided input directly to the function. **Recommendations** Update to version 2.31.0 or later. As a temporary workaround, validate that any user-supplied input is a string before passing it to the `moment.locale()` function.