๐Ÿ” CVE Alert

CVE-2026-17495

MEDIUM 5.9

moment vulnerable to Path Traversal via crafted non-string locale name

CVSS Score
5.9
EPSS Score
0.4%
EPSS Percentile
29th

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().

CWE CWE-27
Vendor moment
Product moment
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for moment moment

Be the first to know when new medium vulnerabilities affecting moment moment are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

moment / moment
2.29.2 < 2.31.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw cna.openjsf.org: https://cna.openjsf.org/security-advisories.html

Credits

๐Ÿ” zolbooo UlisesGascon gilmoreorless mattjohnsonpint