Node.js Windows Module Resolution Privilege Escalation via C:\node_modules Planting (CVE-2026-0775, CVE-2026-0776)

Node.js Windows Module Resolution Privilege Escalation via (TL-2026-1548), also tracked as Node.js Trust Falls, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-04-08. It has no confirmed attribution, affects npm, Inc. / OpenJS Foundation npm CLI, references 2 CVEs (CVE-2026-0775, CVE-2026-0776), maps to 14 MITRE ATT&CK techniques (T1036.005, T1059.007, T1068), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-1548

Threat ID
TL-2026-1548
Also known as
Node.js Trust Falls
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-04-08
Last reviewed
2026-04-08
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, softwaredevelopment, gaming, consumer, criticalinfrastructuredevelopmentteams
Target regions
Global
Detection rules
9
Indicators of compromise
15

Node.js's module resolution algorithm on Windows traverses up to the filesystem root and treats C: ode_modules as a legitimate search location. Because unprivileged Windows users can create this directory, a local low-privileged attacker can plant a malicious module there to gain code execution in the context of a higher-privileged user when a vulnerable application with missing/optional dependencies launches. npm CLI (prior to v11.2.0, CVE-2026-0775) and Discord desktop client (CVE-2026-0776) are confirmed affected; Discord remains unpatched as of publication.

How Node.js Windows Module Resolution Privilege Escalation via works

Node.js's CommonJS module resolution algorithm walks the directory tree upward from the requiring module's location, checking each ancestor directory for a node_modules folder, until it reaches the filesystem root. On POSIX systems the root-level /node_modules directory requires superuser privileges to create, which effectively closes off this final search location as an attack surface. On Windows, however, any unprivileged, standard user account can create C:\node_modules without elevation, because Windows does not restrict directory creation at the drive root the way UNIX restricts writes to /. Node.js maintainers are aware of this behavior (tracked informally since 2013-2014) and have explicitly classified it as a non-vulnerability / working-as-intended design decision, stating that "Node.js trusts the file system in the environment accessible to it" and mapping the underlying weakness to CWE-427 (Uncontrolled Search Path Element) without committing to a runtime fix.

The practical exploitation vector is the widespread JavaScript pattern of "optional dependencies" — packages wrapped in try/catch blocks so that a missing package degrades gracefully rather than crashing the application. Node's require() call still walks the full search path (including C:\node_modules) before the exception is thrown and caught, meaning any planted module at that location is loaded and executed with the privileges of the process performing the require() — even though the developer's intent was for the missing-package case to be silently ignored.

CVE-2026-0775 affects the npm CLI (ZDI-26-043 / ZDI-CAN-25430, CVSS 7.8, CWE-732 Incorrect Permission Assignment for Critical Resource). npm's dependency 'promise-inflight' carries an optional dependency on 'bluebird', which is not bundled with the default Windows Node.js/npm installation. An attacker who first obtains low-privileged code execution (or simply an unprivileged account) can plant C:\node_modules\bluebird.js; any user who subsequently runs npm commands (npm install, npm -l, npm prune, etc.) on that host will execute the attacker's payload in their own user context — a classic local privilege escalation path when a higher-privileged user (e.g., a developer or admin running npm as part of a build/deploy process) is the one invoking npm. ZDI reported this to the npm/Node.js maintainers on 2024-11-13; the vendor acknowledged the report but deemed the behavior intentional. ZDI requested reconsideration on 2025-08-05, announced intent to publish as a 0-day on 2025-12-18, and published the advisory on 2026-01-12 (updated 2026-02-02). npm CLI 11.2.0 subsequently shipped a fix (tracked publicly in npm/cli issue #8939) removing/adjusting the vulnerable optional-dependency resolution path.

CVE-2026-0776 affects the Discord desktop client (ZDI-26-040 / ZDI-CAN-27057, CVSS 7.3, CWE-427). Discord's discord_rpc module depends on the 'ws' WebSocket library, which carries an optional dependency on 'utf-8-validate' for compatibility with older Node.js versions where native UTF-8 validation is unavailable. Because Discord auto-starts on user login by default and is one of the most widely installed consumer applications on Windows, an attacker who plants C:\node_modules\utf-8-validate.js achieves code execution in the victim's user context essentially every time Discord launches — including automatically at every login, without any further user interaction beyond the initial system compromise needed to write the file. ZDI reported this to Discord on 2025-07-08; Discord disputed the classification and reaffirmed on 2025-09-15 and 2025-12-10 that local-attack scenarios are out of scope for its bug bounty program. ZDI announced intent to publish as a 0-day on 2025-12-11 and released the public advisory on 2026-01-09, with the researcher publicly demonstrating exploitation via a proof-of-concept video showing calc.exe execution triggered purely by launching Discord. As of publication, Discord remains unpatched and has stated no fix is planned; the only mitigation is restricting/monitoring interaction with the product, or setting the WS_NO_UTF_8_VALIDATE environment variable to short-circuit the optional-dependency load path.

Beyond the two confirmed/published CVEs, ZDI's broader research (published as the blog post "Node.js Trust Falls: Dangerous Module Resolution on Windows") identified the same root-cause pattern in MongoDB Compass (tracked as COMPASS-9058) and MongoDB Shell/mongosh (tracked as MONGOSH-2028), and flagged the pattern as systemically present across the broader Electron and Node.js application ecosystem — any Electron app, Next.js/React tooling, or general Node.js application on Windows that uses the try/catch optional-dependency pattern is potentially exploitable by the same C:\node_modules planting technique. Node.js core maintainers' refusal to treat the upward directory-walk-to-root behavior as a vulnerability means this class of bug will likely continue to surface in additional downstream applications until individual vendors patch their own optional-dependency handling or Node.js changes its default resolution behavior on Windows.

MITRE ATT&CK techniques used in TL-2026-1548

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1211 Exploitation for Stealth; T1218 System Binary Proxy Execution; T1574.009 Path Interception by Unquoted Path

Execution

T1059.007 JavaScript

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1547 Boot or Logon Autostart Execution

Initial Access

T1078.003 Local Accounts

Discovery

T1083 File and Directory Discovery

Impact

T1489 Service Stop

Persistence

T1505 Server Software Component; T1547 Boot or Logon Autostart Execution; T1547.001 Registry Run Keys / Startup Folder

stealth

T1574 Hijack Execution Flow; T1574.001 DLL

Affected products and versions in Node.js Windows Module Resolution Privilege Escalation via

  • npm, Inc. / OpenJS Foundation — npm CLI
    Vulnerable versions: prior to 10.9.0; 10.9.0
    Fixed in: 11.2.0 and later
  • Discord Inc. — Discord Client
    Vulnerable versions: 1.0.9196; current release as of publication
  • MongoDB Inc. — MongoDB Compass
    Vulnerable versions: tracked as COMPASS-9058, version not disclosed
  • MongoDB Inc. — MongoDB Shell (mongosh)
    Vulnerable versions: tracked as MONGOSH-2028, version not disclosed

Remediation for Node.js Windows Module Resolution Privilege Escalation via

Patches

  • npm CLI 11.2.0 (fixes CVE-2026-0775)
  • No patch available for Discord Client as of publication (CVE-2026-0776) — vendor has classified local-attack scenarios as out of bug-bounty scope

Immediate actions

  • Restrict write access to C:\node_modules (and the root of any drive npm/Node applications may run from) to Administrators only via NTFS ACLs
  • Audit hosts for the presence of an existing, unauthorized C:\node_modules directory or unexpected .js files planted at drive root
  • Set the WS_NO_UTF_8_VALIDATE environment variable on hosts running Discord to bypass the vulnerable optional-dependency load path
  • Restrict or monitor local code execution capability for standard/unprivileged users on hosts where npm or Discord is used by higher-privileged accounts

Workarounds

  • Set WS_NO_UTF_8_VALIDATE environment variable to prevent Discord's ws library from attempting to load the optional utf-8-validate module
  • Pre-create C:\node_modules with restrictive ACLs (Administrators-only write) to preempt unprivileged planting
  • Restrict interaction with affected products by unprivileged/untrusted local accounts, per ZDI's stated mitigation guidance

Longer-term hardening

  • Upgrade npm CLI to version 11.2.0 or later on all Windows hosts
  • Deploy EDR/behavioral detection for child-process execution originating from node.exe/npm.cmd/Discord.exe loading scripts from C:\node_modules
  • Track vendor guidance for Discord; no official patch is available as of publication — consider compensating controls or alternate deployment (e.g., sandboxed/containerized Discord) for privileged users
  • Review all internally developed and third-party Electron/Node.js Windows applications for use of the try/catch optional-dependency pattern and audit their exposure to the same root-node_modules planting technique
  • Advocate for / track upstream Node.js changes to Windows module resolution search-path defaults

CVEs associated with Node.js Windows Module Resolution Privilege Escalation via

CVE-2026-0775, CVE-2026-0776

Weaknesses (CWE) in Node.js Windows Module Resolution Privilege Escalation via

CWE-427, CWE-732

Timeline of Node.js Windows Module Resolution Privilege Escalation via

  • ZDI reports the npm CLI C:\node_modules module-resolution privilege escalation issue (later CVE-2026-0775) to the vendor; vendor acknowledges but deems the behavior intentional/working-as-designed.
  • ZDI reports the equivalent issue in the Discord desktop client (later CVE-2026-0776) to Discord.
  • ZDI requests the npm/Node.js maintainers reconsider their classification of the module-resolution behavior as intentional.
  • Discord disputes the vulnerability classification, asserting local-attack scenarios fall outside its bug bounty program's scope.
  • Discord reaffirms its position that local attacks are out of scope for remediation.
  • ZDI announces intent to publish the Discord vulnerability as a 0-day advisory following vendor non-response.
  • ZDI announces intent to publish the npm CLI vulnerability as a 0-day advisory.
  • ZDI publishes advisory ZDI-26-040 for CVE-2026-0776 (Discord), which remains unpatched.
  • Community member files npm/cli GitHub issue #8939 flagging CVE-2026-0775 to maintainers for review.
  • ZDI publishes advisory ZDI-26-043 for CVE-2026-0775 (npm CLI), tracked as ZDI-CAN-25430.
  • NVD publishes formal CVE records for both CVE-2026-0775 (CVSS 7.8) and CVE-2026-0776 (CVSS 7.3).
  • ZDI updates the ZDI-26-043 advisory for CVE-2026-0775.
  • Zero Day Initiative publishes the consolidated technical blog post "Node.js Trust Falls: Dangerous Module Resolution on Windows," detailing the root-cause pattern, both CVEs, additional affected products (MongoDB Compass, mongosh), and demonstrating exploitation against Discord via a calc.exe proof-of-concept.

Sources cited for Node.js Windows Module Resolution Privilege Escalation via

Threats related to Node.js Windows Module Resolution Privilege Escalation via

Detection coverage for TL-2026-1548

As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1548 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats