CVE-2024-37372

All FrameworksNode.jsCWE-22CVE-2024-37372

CVE-2024-37372

State: PUBLISHED · Published: 2025-01-09 · Updated: 2025-05-02 · Assigner: hackerone
Description
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2024/37xxx/CVE-2024-37372.json