Логотип exploitDog
bind:"CVE-2025-55130"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-55130"

Количество 7

Количество 7

ubuntu логотип

CVE-2025-55130

14 дней назад

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2025-55130

14 дней назад

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2025-55130

14 дней назад

A flaw in Node.js\u2019s Permissions model allows attackers to bypass ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-62wc-jj78-f4f6

14 дней назад

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2026-00545

22 дня назад

Уязвимость программной платформы Node.js, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю скомпрометировать систему

CVSS3: 7.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0301-1

8 дней назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0295-1

9 дней назад

Security update for nodejs22

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 7.1
0%
Низкий
14 дней назад
nvd логотип
CVE-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 7.1
0%
Низкий
14 дней назад
debian логотип
CVE-2025-55130

A flaw in Node.js\u2019s Permissions model allows attackers to bypass ...

CVSS3: 7.1
0%
Низкий
14 дней назад
github логотип
GHSA-62wc-jj78-f4f6

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 7.1
0%
Низкий
14 дней назад
fstec логотип
BDU:2026-00545

Уязвимость программной платформы Node.js, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю скомпрометировать систему

CVSS3: 7.7
0%
Низкий
22 дня назад
suse-cvrf логотип
SUSE-SU-2026:0301-1

Security update for nodejs22

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:0295-1

Security update for nodejs22

9 дней назад

Уязвимостей на страницу