{"schema_version":"1.7.5","id":"CVE-2017-14849","published":"2017-09-28T01:29:02.543Z","modified":"2026-07-08T11:48:03.398132Z","related":["SUSE-SU-2019:14246-1"],"details":"Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to \"..\" handling was incompatible with the pathname validation used by unspecified community modules.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nodejs/node","events":[{"introduced":"a2a2ff4817f359768c846587983439f7b29d1cf5"},{"last_affected":"a2a2ff4817f359768c846587983439f7b29d1cf5"}],"database_specific":{"cpe":"cpe:2.3:a:nodejs:node.js:8.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.5.0"},{"last_affected":"8.5.0"}],"source":"CPE_STRING"}}],"versions":["8.5.0","v8.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14849.json"}}],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101056"},{"type":"FIX","url":"https://nodejs.org/en/blog/vulnerability/september-2017-path-validation/"},{"type":"FIX","url":"https://twitter.com/nodejs/status/913131152868876288"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}