
🛡️ Node.js Module Resolution Local Privilege Escalation (Windows)
Published Wednesday, September 30, 2026 at 05:46 PM PT BLUF: Windows systems running Node.js applications are at risk from a local privilege escalation vulnerability in npm CLI’s module resolution system. Discord desktop app confirmed affected (CVE-2026-0776). No patch available. Immediate action: audit Windows systems for Node.js installations; restrict local user access on sensitive machines; prepare to isolate and update Discord and other Node.js applications pending vendor fixes. ...