Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 15 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale(). | |
| Title | moment vulnerable to Path Traversal via crafted non-string locale name | |
| Weaknesses | CWE-27 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: openjs
Published:
Updated: 2026-09-15T05:40:55.263Z
Reserved: 2026-07-26T13:49:41.562Z
Link: CVE-2026-17495
No data.
Status : Received
Published: 2026-09-15T06:16:57.597
Modified: 2026-09-15T06:16:57.597
Link: CVE-2026-17495
OpenCVE Enrichment
No data.