{"id":"GHSA-4p3w-j4w9-5jqw","summary":"moment vulnerable to Path Traversal via crafted non-string locale name","details":"### Impact\n\nmoment before 2.31.0 is vulnerable to path traversal in `moment.locale()`. When an application passes a non-string, attacker-influenced value to `moment.locale()`, a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for [CVE-2022-24785](https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4).\n\nThis affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.\n\n### Patches\n\nThis issue is patched in moment 2.31.0.\n\n### Workarounds\n\nValidate that any user-supplied input is a string before passing it to `moment.locale()`.","aliases":["CVE-2026-17495"],"modified":"2026-09-30T00:00:03.858466235Z","published":"2026-09-29T23:46:02Z","database_specific":{"nvd_published_at":"2026-09-15T06:16:57Z","cwe_ids":["CWE-27"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-29T23:46:02Z"},"references":[{"type":"WEB","url":"https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17495"},{"type":"WEB","url":"https://github.com/moment/moment/pull/6386"},{"type":"WEB","url":"https://github.com/moment/moment/commit/5f7d983c9881e65e07574de9dda3190d99520c07"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/moment/moment"},{"type":"WEB","url":"https://github.com/moment/moment/releases/tag/2.31.0"}],"affected":[{"package":{"name":"moment","ecosystem":"npm","purl":"pkg:npm/moment"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.29.2"},{"fixed":"2.31.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-4p3w-j4w9-5jqw/GHSA-4p3w-j4w9-5jqw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}