CVE-2026-33672 describes a medium-severity method injection vulnerability (CVSS 5.3) affecting picomatch versions prior to 4.0.4, 3.0.2, and 2.3.2. This flaw allows specially crafted POSIX bracket expressions to inject inherited method names into generated regular expressions, leading to incorrect glob matching behavior. While not enabling remote code execution, this can cause security-relevant logic errors in applications relying on glob patterns for filtering, validation, or access control. The vulnerability is exploitable over the network with low complexity and no user interaction, impacting systems processing untrusted glob patterns. There is no evidence of active exploitation or public exploit code, and users are advised to upgrade to patched versions or sanitize untrusted input.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.2CPE matchmatch criteria | cpe:2.3:a:jonschlinkert:picomatch:*:*:*:*:*:node.js:*:* | ||
>= 3.0.0, < 3.0.2CPE matchmatch criteria | cpe:2.3:a:jonschlinkert:picomatch:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.0.4CPE matchmatch criteria | cpe:2.3:a:jonschlinkert:picomatch:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.