DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-17495: CVE-2026-17495: Path Traversal via Type Confusion in Moment.js Dynamic Locale Loading

CVE-2026-17495: Path Traversal via Type Confusion in Moment.js Dynamic Locale Loading

Vulnerability ID: CVE-2026-17495
CVSS Score: 5.9
Published: 2026-09-29

Moment.js versions 2.29.2 through 2.30.1 are vulnerable to a Path Traversal flaw (CWE-27) on server-side Node.js environments when dynamic locales are configured. The vulnerability stems from an object-coercion bypass in the locale-name sanitization routine, which assumes incoming variables are string primitives. An attacker can pass a structured object with custom 'match' and 'toString' properties to bypass regex-based directory checks, leading to arbitrary file loading via Node's internal 'require()' call.

TL;DR

An incomplete fix in Moment.js allows attackers to bypass directory traversal protections by passing a structured object instead of a string to moment.locale(), triggering dynamic execution or file loading via type confusion.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-27 (Path Traversal), CWE-843 (Type Confusion)
  • Attack Vector: Network
  • CVSS v3.1: 5.9 (Medium)
  • EPSS Score: 0.00357 (0.357% probability of exploitation)
  • Impact: Local File Inclusion (LFI) / Potential Remote Code Execution (RCE)
  • Exploit Status: Proof-of-Concept Available
  • CISA KEV Status: Not Listed

Affected Systems

  • Server-side applications built on Node.js using Moment.js versions 2.29.2 through 2.30.1.
  • moment: >= 2.29.2, <= 2.30.1 (Fixed in: 2.31.0)

Code Analysis

Commit: 5f7d983

[bugfix] Normalize lazy-loaded locale names (#6386)

Mitigation Strategies

  • Upgrade Moment.js package dependency to version 2.31.0 or newer.
  • Manually enforce 'typeof' checks on parameters passed to moment.locale() to drop non-string objects.
  • Enforce '--frozen-intrinsics' in Node.js execution environments to mitigate runtime prototype exploitation vectors.

Remediation Steps:

  1. Identify all direct and indirect imports of 'moment' inside 'package.json'.
  2. Execute 'npm install moment@2.31.0' or update the package version in the dependency manifest.
  3. Implement a middleware wrapper checking the types of all user-supplied parameters before passing them to internal localization modules.
  4. Deploy continuous static analysis scanning rules like Semgrep to detect dynamically generated locales in code blocks.

References


Read the full report for CVE-2026-17495 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)