CVE-2025-55130 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By…
Critical CVSS: 9.1

CVE-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise.
This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
Vendor
Nodejs
Product
Node.js
CWE
CWE-289
Yayın Tarihi
2026-01-20 21:16:03
Güncelleme
2026-02-03 21:29:50
Source Identifier
support@hackerone.com
KEV Date Added
-

Kategoriler

Referanslar