Vulnerability GHSA-4p3w-j4w9-5jqw

Medium Risk
MEDIUM RISK
CVSS Score: 5.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 hours ago
September 29, 2026 at 11:46 PM UTC
moment vulnerable to Path Traversal via crafted non-string locale name
2.29.2 - 2.30.1
2.29.2 - 2.30.1

Summary

moment vulnerable to Path Traversal via crafted non-string locale name

Details

Impact

moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.

This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.

Patches

This issue is patched in moment 2.31.0.

Workarounds

Validate that any user-supplied input is a string before passing it to moment.locale().

Impacted packages

Timeline

Published
4 hours ago
September 29, 2026 at 11:46 PM UTC
Fixed (2.31.0)
Unknown
Unknown
Last Modified
4 hours ago
September 30, 2026 at 12:00 AM UTC