GHSA-4p3w-j4w9-5jqwMediumCVSS 5.9
moment vulnerable to Path Traversal via crafted non-string locale name
🔗 CVE IDs covered (1)
📋 Description
Impact
moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.
This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.
Patches
This issue is patched in moment 2.31.0.
Workarounds
Validate that any user-supplied input is a string before passing it to moment.locale().
🎯 Affected products1
- npm/moment:>= 2.29.2, < 2.31.0
🔗 References (7)
- https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw
- https://nvd.nist.gov/vuln/detail/CVE-2026-17495
- https://github.com/moment/moment/pull/6386
- https://github.com/moment/moment/commit/5f7d983c9881e65e07574de9dda3190d99520c07
- https://cna.openjsf.org/security-advisories.html
- https://github.com/moment/moment/releases/tag/2.31.0
- https://github.com/advisories/GHSA-4p3w-j4w9-5jqw