Listen to this Post
This vulnerability affects the JavaScript date library moment, specifically versions 2.29.2 through 2.30.1. It is a path traversal issue that arises when an application passes a non-string, attacker-influenced value to the `moment.locale()` function. The root cause lies in an incomplete fix for CVE-2022-24785. In version 2.29.2, a validation check was added to prevent strings containing path separators from being used as locale names. However, this guard assumes that the input is a string. A specially crafted object can bypass this check by implementing a `match()` method that satisfies the validation logic while its `toString()` method returns a traversal path. When `moment.locale()` processes this object, it eventually reaches an internal `require()` call with attacker-controlled path segments. This allows an attacker to load a file from an arbitrary path on the server. The vulnerability primarily affects npm (server-side) users who pass user-provided input directly to moment.locale(). Plain string input is not affected, as the existing validation correctly rejects strings that contain path separators. The issue is fixed in moment version 2.31.0. As a workaround, developers should validate that any user-supplied input is a string before passing it to moment.locale(). This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785. The CWE associated with this vulnerability is CWE-27, which is a path traversal issue involving ‘dir/../../filename’. The CVSS score is not provided, but the severity is rated as moderate. The vulnerability was published on September 15, 2026, and the advisory was updated on September 29, 2026. The patch is available in moment 2.31.0. Users are advised to upgrade to version 2.31.0 or later to mitigate this issue. The vulnerability was reported by zolbooo, with remediation by UlisesGascon and mattjohnsonpint, and coordination by gilmoreorless. The affected package is pkg:npm/moment. The Debian security tracker lists version 2.29.4+ds-1 as vulnerable for bookworm and trixie, while 2.31.0+ds1-1 is fixed for forky and sid. The vulnerability is an incomplete fix for CVE-2022-24785. The guard assumes the input is a string, so an object whose `match()` method satisfies the check while its `toString()` returns a traversal path reaches an internal `require()` call with attacker-controlled path segments.
DailyCVE Form:
Platform: moment npm
Version: before 2.31.0
Vulnerability: Path Traversal
Severity: Moderate
date: 2026-09-15
Prediction: 2026-09-29
What Undercode Say:
npm list moment npm install [email protected]
const moment = require('moment');
const maliciousLocale = {
match: () => true,
toString: () => '../../../../etc/passwd'
};
moment.locale(maliciousLocale);
Exploit: (Educational Purposes!)
const moment = require('moment');
const payload = {
match: () => true,
toString: () => '../../../../../../tmp/evil'
};
moment.locale(payload);
Protection: from this CVE
if (typeof userInput === 'string') {
moment.locale(userInput);
}
npm update moment
Impact:
Server-side path traversal; load attacker-controlled file.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

