Threat Advisory

Moment Flaw Lets Attackers Bypass Locale Name Validation

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in moment. Affected versions include 2.29.2 and prior to 2.31.0. These vulnerabilities pose a medium risk.

CVE-2026-17495 (CVSS 5.9 — Severity): moment before 2.31.0 is vulnerable to path traversal in `moment.locale`. An attacker-influenced value can bypass locale name validation and cause moment to load a file from an attacker-controlled path.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in moment. Affected versions include 2.29.2 and prior to 2.31.0. These vulnerabilities pose a medium risk.

CVE-2026-17495 (CVSS 5.9 — Severity): moment before 2.31.0 is vulnerable to path traversal in `moment.locale`. An attacker-influenced value can bypass locale name validation and cause moment to load a file from an attacker-controlled path.[emaillocker id="1283"]

CVE-2022-24785: This vulnerability was previously fixed in version 2.29.2 but has been bypassed by the introduction of a new attack vector in version 2.31.0.

These vulnerabilities collectively present a risk to server-side users who have not updated to the latest version.

RECOMMENDATION:

We recommend you to update moment to version 2.31.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu