Two high-severity flaws affecting widely used JavaScript packages were disclosed and patched, exposing Node.js applications to file-system escape and HTTP traffic interception risks. In tmp 0.2.6, CVE-2026-49982 allows path traversal through type confusion in the internal _assertPath guard: non-string values such as arrays, buffers, or crafted objects can bypass checks for .. and later stringify into traversal paths, letting files or directories be created outside the intended temporary directory. The issue affects applications that pass untrusted data into APIs including tmp.file, tmp.dir, and related synchronous and temporary-name functions, and it is fixed in tmp 0.2.7.
A separate flaw in Axios, tracked as CVE-2026-44494, affects versions 1.0.0 through before 1.16.0 and turns existing Object.prototype pollution elsewhere in an application into a full man-in-the-middle condition. Because Axios reads config.proxy through normal prototype-chain property access and does not define proxy as an own property by default, an attacker who can poison the prototype can force requests through an attacker-controlled proxy, exposing and altering HTTP traffic and credentials. Axios fixed the issue in 1.16.0, while reporting on the tmp bug noted a CVSS:3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L and warned that raw JSON bodies or complex query objects passed directly into library options increase exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Axios versions 1.0.0 through before 1.16.0 were found vulnerable to a prototype pollution gadget in config.proxy that could escalate existing Object.prototype pollution into a man-in-the-middle attack. The flaw was fixed in Axios version 1.16.0.
A path traversal vulnerability in tmp 0.2.6 allowed non-string values to bypass the _assertPath guard and create files or directories outside the intended temporary directory. The issue was fixed in tmp version 0.2.7 by enforcing string validation before traversal checks.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.