Description
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().
Published: 2026-09-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A specially crafted non‑string object can be passed to moment.locale(). The function assumes the value is a string; when the object’s match() method passes the guard and its toString() returns a traversal path, the library internally calls require() with that attacker‑controlled path. This allows the loading of arbitrary modules or files, which can lead to code execution on the server. The flaw maps to CWE‑22 (Path Traversal) and CWE‑27 (Duplicate Logic).

Affected Systems

Moment versions 2.29.2 through 2.30.1 are vulnerable. The issue primarily affects deployments that use npm and directly forward user‑supplied locale names to moment.locale(). The fix is available in moment 2.31.0 and later.

Risk and Exploitability

The CVSS score is 5.9, indicating moderate severity, while the EPSS score is below 1%, implying a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. To exploit, an attacker must influence the locale parameter in a server‑side JavaScript context, such as by injecting a crafted object into an API request or configuration that calls moment.locale().

Generated by OpenCVE AI on September 17, 2026 at 18:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade moment to 2.31.0 or later using npm or your package manager
  • Validate that any value passed to moment.locale() is explicitly a string before calling it
  • If an upgrade cannot be applied immediately, add a runtime check that rejects non‑string locale names to prevent the traversal guard from being bypassed

Generated by OpenCVE AI on September 17, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4p3w-j4w9-5jqw moment vulnerable to Path Traversal via crafted non-string locale name
History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().
Title moment vulnerable to Path Traversal via crafted non-string locale name
Weaknesses CWE-27
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-15T17:49:57.391Z

Reserved: 2026-07-26T13:49:41.562Z

Link: CVE-2026-17495

cve-icon Vulnrichment

Updated: 2026-09-15T17:49:51.935Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T06:16:57.597

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-17495

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T05:40:55Z

Links: CVE-2026-17495 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-27

    Path Traversal: 'dir/../../filename'