Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 15 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale(). | |
| Title | moment vulnerable to Path Traversal via crafted non-string locale name | |
| Weaknesses | CWE-27 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: openjs
Published:
Updated: 2026-09-15T17:49:57.391Z
Reserved: 2026-07-26T13:49:41.562Z
Link: CVE-2026-17495
Updated: 2026-09-15T17:49:51.935Z
Status : Awaiting Analysis
Published: 2026-09-15T06:16:57.597
Modified: 2026-09-16T19:40:00.317
Link: CVE-2026-17495
OpenCVE Enrichment
Updated: 2026-09-16T06:30:11Z