CVE-2025-55130: Vulnerability in nodejs node
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
AI Analysis
Technical Summary
This vulnerability in Node.js arises from a flaw in the permissions model that permits bypassing the --allow-fs-read and --allow-fs-write flags via crafted relative symbolic link paths. By chaining directories and symlinks, an attacker can escape the intended directory restrictions and perform arbitrary file read and write operations beyond the allowed scope. This undermines the expected isolation and can lead to potential system compromise. The issue affects Node.js versions 20, 22, 24, and 25, specifically the versions 20.19.6, 22.21.1, 24.12.0, and 25.2.1 as identified. Red Hat has released security advisories and patches for their Node.js builds to remediate this vulnerability.
Potential Impact
Successful exploitation allows an attacker with limited permissions to bypass filesystem read/write restrictions imposed by Node.js's permission model. This can lead to unauthorized reading and writing of arbitrary files outside the permitted directory, breaking isolation guarantees. The impact includes potential exposure of sensitive information and possible system compromise due to unauthorized file manipulation. The CVSS score of 7.1 reflects high confidentiality and integrity impact with no impact on availability.
Mitigation Recommendations
Red Hat has published security advisories and issued updated Node.js packages that fix this vulnerability. Users of affected Node.js versions on Red Hat Enterprise Linux should apply the official security updates as detailed in Red Hat advisories (e.g., RHSA-2026:2899). Since this is not a cloud service, remediation requires updating the affected Node.js packages to the fixed versions provided by the vendor. Patch status is confirmed by Red Hat advisories. No alternative mitigations are specified beyond applying the vendor-provided updates.
CVE-2025-55130: Vulnerability in nodejs node
Description
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
CVSS v3.0
Score 7.1high
Affected software
pkg:github/nodejs/nodeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Node.js arises from a flaw in the permissions model that permits bypassing the --allow-fs-read and --allow-fs-write flags via crafted relative symbolic link paths. By chaining directories and symlinks, an attacker can escape the intended directory restrictions and perform arbitrary file read and write operations beyond the allowed scope. This undermines the expected isolation and can lead to potential system compromise. The issue affects Node.js versions 20, 22, 24, and 25, specifically the versions 20.19.6, 22.21.1, 24.12.0, and 25.2.1 as identified. Red Hat has released security advisories and patches for their Node.js builds to remediate this vulnerability.
Potential Impact
Successful exploitation allows an attacker with limited permissions to bypass filesystem read/write restrictions imposed by Node.js's permission model. This can lead to unauthorized reading and writing of arbitrary files outside the permitted directory, breaking isolation guarantees. The impact includes potential exposure of sensitive information and possible system compromise due to unauthorized file manipulation. The CVSS score of 7.1 reflects high confidentiality and integrity impact with no impact on availability.
Mitigation Recommendations
Red Hat has published security advisories and issued updated Node.js packages that fix this vulnerability. Users of affected Node.js versions on Red Hat Enterprise Linux should apply the official security updates as detailed in Red Hat advisories (e.g., RHSA-2026:2899). Since this is not a cloud service, remediation requires updating the affected Node.js packages to the fixed versions provided by the vendor. Patch status is confirmed by Red Hat advisories. No alternative mitigations are specified beyond applying the vendor-provided updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hackerone
- Date Reserved
- 2025-08-07T15:00:05.576Z
- Cvss Version
- 3.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-55130","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2899","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:1843","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:1842","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2422","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2421","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2420","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2768","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2767","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2864","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2783","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2782","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2781","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7386","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7387","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6402","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6431","vendor":"Red Hat"}]
Threat ID: 696feab04623b1157c4e3b6c
Added to database: 01/20/2026, 20:50:56 UTC
Last enriched: 07/15/2026, 08:19:59 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 267
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.