PT-2026-91861 · Npm · Moment

·

CVE-2026-17495

·

Published

2026-09-15

·

Updated

2026-09-30

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions moment versions 2.29.2 through 2.30.1
Description A path-traversal issue exists when a specially crafted non-string object is passed to the moment.locale() function. The internal guard assumes the input is a string; however, an object with a match() method that satisfies the check and a toString() method that returns a traversal path can reach an internal require() call with attacker-controlled path segments. This primarily affects server-side npm users who pass user-provided input directly to the function.
Recommendations Update to version 2.31.0 or later. As a temporary workaround, validate that any user-supplied input is a string before passing it to the moment.locale() function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17495
GHSA-4P3W-J4W9-5JQW

Affected Products

Moment