[CLSA-2026:1785512441] alt-nodejs20-nodejs: Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-31 15:40:58 UTC
Description:
- CVE-2026-48617: gate process.report.writeReport() on the fs.write permission so diagnostic reports cannot escape the --allow-fs-write allow-list - CVE-2026-48935: disable FileHandle.utimes() when the Permission Model is enabled so file timestamps cannot be changed with read-only access
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-6.el7.x86_64.rpm
    sha:634d4f8bf79143cea17a6452b281a642db8ba0503d98a9e5d4653037c119459e
  • alt-nodejs20-nodejs-devel-20.20.2-6.el7.x86_64.rpm
    sha:205bc5c7945749e38870797a0d8f6c7d3f7c9ca0caff4b04d7b94b2143ab1f6a
  • alt-nodejs20-nodejs-docs-20.20.2-6.el7.noarch.rpm
    sha:4b0031d8dcdeff26a1ed68c38937791ceccf44dbece54ba5f97dc854960b592f
  • alt-nodejs20-npm-10.8.2-20.20.2.6.el7.x86_64.rpm
    sha:d77bca906c15a862c2b18bb91f7949cde68bd4369b612b6ab1aa85037d83583c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.