CVE-2026-17495: Path Traversal via Type Confusion in Moment.js Dynamic Locale Loading
Vulnerability ID: CVE-2026-17495
CVSS Score: 5.9
Published: 2026-09-29
Moment.js versions 2.29.2 through 2.30.1 are vulnerable to a Path Traversal flaw (CWE-27) on server-side Node.js environments when dynamic locales are configured. The vulnerability stems from an object-coercion bypass in the locale-name sanitization routine, which assumes incoming variables are string primitives. An attacker can pass a structured object with custom 'match' and 'toString' properties to bypass regex-based directory checks, leading to arbitrary file loading via Node's internal 'require()' call.
TL;DR
An incomplete fix in Moment.js allows attackers to bypass directory traversal protections by passing a structured object instead of a string to moment.locale(), triggering dynamic execution or file loading via type confusion.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-27 (Path Traversal), CWE-843 (Type Confusion)
- Attack Vector: Network
- CVSS v3.1: 5.9 (Medium)
- EPSS Score: 0.00357 (0.357% probability of exploitation)
- Impact: Local File Inclusion (LFI) / Potential Remote Code Execution (RCE)
- Exploit Status: Proof-of-Concept Available
- CISA KEV Status: Not Listed
Affected Systems
- Server-side applications built on Node.js using Moment.js versions 2.29.2 through 2.30.1.
-
moment: >= 2.29.2, <= 2.30.1 (Fixed in:
2.31.0)
Code Analysis
Commit: 5f7d983
[bugfix] Normalize lazy-loaded locale names (#6386)
Mitigation Strategies
- Upgrade Moment.js package dependency to version 2.31.0 or newer.
- Manually enforce 'typeof' checks on parameters passed to moment.locale() to drop non-string objects.
- Enforce '--frozen-intrinsics' in Node.js execution environments to mitigate runtime prototype exploitation vectors.
Remediation Steps:
- Identify all direct and indirect imports of 'moment' inside 'package.json'.
- Execute 'npm install moment@2.31.0' or update the package version in the dependency manifest.
- Implement a middleware wrapper checking the types of all user-supplied parameters before passing them to internal localization modules.
- Deploy continuous static analysis scanning rules like Semgrep to detect dynamically generated locales in code blocks.
References
- GHSA-4p3w-j4w9-5jqw Security Advisory
- OpenJS Foundation CNA security page
- Fix Commit
- Fix Pull Request
- Moment 2.31.0 Release Notes
- NVD Record
- CVE.org Authority Record
- Wiz Vulnerability Entry
Read the full report for CVE-2026-17495 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)