PT-2026-91861 · Npm · Moment
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
moment versions 2.29.2 through 2.30.1
Description
A path-traversal issue exists when a specially crafted non-string object is passed to the
moment.locale() function. The internal guard assumes the input is a string; however, an object with a match() method that satisfies the check and a toString() method that returns a traversal path can reach an internal require() call with attacker-controlled path segments. This primarily affects server-side npm users who pass user-provided input directly to the function.Recommendations
Update to version 2.31.0 or later.
As a temporary workaround, validate that any user-supplied input is a string before passing it to the
moment.locale() function.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moment