Impact
A specially crafted non‑string object can be passed to moment.locale(). The function assumes the value is a string; when the object’s match() method passes the guard and its toString() returns a traversal path, the library internally calls require() with that attacker‑controlled path. This allows the loading of arbitrary modules or files, which can lead to code execution on the server. The flaw maps to CWE‑22 (Path Traversal) and CWE‑27 (Duplicate Logic).
Affected Systems
Moment versions 2.29.2 through 2.30.1 are vulnerable. The issue primarily affects deployments that use npm and directly forward user‑supplied locale names to moment.locale(). The fix is available in moment 2.31.0 and later.
Risk and Exploitability
The CVSS score is 5.9, indicating moderate severity, while the EPSS score is below 1%, implying a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. To exploit, an attacker must influence the locale parameter in a server‑side JavaScript context, such as by injecting a crafted object into an API request or configuration that calls moment.locale().
OpenCVE Enrichment
Github GHSA