Disclosure summary
### Impact moment before 2.31.0 is vulnerable to path traversal in `moment.locale()`. When an application passes a non-string, attacker-influenced value to `moment.locale()`, a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for [CVE-2022-24785](https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4). This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators. ### Patches This issue is patched in moment 2.31.0. ### Workarounds Validate that any user-supplied input is a string before passing it to `moment.locale()`.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-4p3w-j4w9-5jqw
Open original source · Updated Sep 29, 2026
moment vulnerable to Path Traversal via crafted non-string locale name
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | moment | >= 2.29.2, < 2.31.0 | 2.31.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T19:46:02-04:00
MODIFIED 2026-09-29T19:46:04-04:00
INGESTED 2026-10-06T11:43:09-04:00