Commit aa8d6b9384a for nodejs

commit aa8d6b9384ade787d5a74742102c61b0287fa100
Author: Rafael Gonzaga <rafael.nunu@hotmail.com>
Date:   Wed Oct 7 15:36:17 2026 +0200

    doc: clarify node binary misuse after compromise

    Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
    PR-URL: https://github.com/nodejs/node/pull/66530
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
    Reviewed-By: James M Snell <jasnell@gmail.com>
    Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
    Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>

diff --git a/SECURITY.md b/SECURITY.md
index 7afe640ecf6..ff66cd097e6 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -264,7 +264,12 @@ then untrusted input must not lead to arbitrary JavaScript code execution.

 * The developers and infrastructure that run it.
 * The operating system that Node.js is running under and its configuration,
-  along with anything under the control of the operating system.
+  along with anything under the control of the operating system. An attacker
+  who can already run commands on the host and uses an official, signed
+  Node.js binary to execute malicious JavaScript does not exploit a
+  vulnerability in Node.js. A code signature identifies the publisher of the
+  Node.js binary; it is not a statement about the trustworthiness of the
+  scripts that binary executes.
 * The deployment network environment for the privacy of traffic and routing
   decisions, including internal networks through which Node.js traffic passes
   and configured HTTP(S) proxy servers. Built-in proxy support is intended to