AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-17495.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Impact moment before 2.31.0 is vulnerable to path traversal in `moment.locale()`. When an application passes a non-string, attacker-influenced value to `moment.locale()`, a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for [CVE-2022-24785](https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4). This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators. ### Patches This issue is patched in moment 2.31.0. ### Workarounds Validate that any user-supplied input is a string before passing it to `moment.locale()`.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-4p3w-j4w9-5jqw

Open original source · Updated Sep 29, 2026

moment vulnerable to Path Traversal via crafted non-string locale name

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npmmoment>= 2.29.2, < 2.31.02.31.0

Original records & references

PUBLISHED 2026-09-29T19:46:02-04:00
MODIFIED 2026-09-29T19:46:04-04:00
INGESTED 2026-10-06T11:43:09-04:00