A flaw in Node.js’s Permissions model allows attackers to bypass --allow-fs-read and --allow-fs-write restrictions using crafted relative symlink… (CVE-2025-55130)
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
AI Analysis
Technical Summary
The advisory covers a set of security issues affecting Red Hat Hardened Images RPMs, particularly Node.js 20 packages. One highlighted vulnerability (CVE-2025-59464) involves a memory leak in Node.js's OpenSSL integration when converting X.509 certificate fields to UTF-8, causing memory to be allocated without being freed. This can be exploited remotely via repeated TLS connections to cause resource exhaustion and denial of service. The advisory lists multiple CVEs and CWE categories related to resource allocation, authentication, and information exposure. The update includes new RPM versions for nodejs20 and related components. However, the vendor advisory does not explicitly state that a fix for CVE-2025-59464 or other CVEs is currently available or deployed, and mitigation options for this specific memory leak are noted as unavailable or insufficient per Red Hat criteria.
Potential Impact
The primary impact is denial of service through resource exhaustion caused by a memory leak in Node.js's OpenSSL integration. Remote attackers can trigger steady memory growth by repeatedly establishing TLS connections, potentially leading to application or system instability. Other listed CVEs and CWEs suggest additional security concerns related to authentication bypass, information exposure, and resource management, but detailed impact descriptions are limited. No known exploits in the wild have been reported.
Mitigation Recommendations
The vendor advisory indicates that mitigation for the Node.js memory leak (CVE-2025-59464) is either not available or does not meet Red Hat's criteria for deployment. No explicit patch availability is confirmed in the advisory text. Users should monitor Red Hat's official errata and update channels for forthcoming fixes. Until a fix is released, consider limiting exposure of affected services to untrusted networks or applying any vendor-recommended workarounds if provided in future advisories.
A flaw in Node.js’s Permissions model allows attackers to bypass --allow-fs-read and --allow-fs-write restrictions using crafted relative symlink… (CVE-2025-55130)
Description
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The advisory covers a set of security issues affecting Red Hat Hardened Images RPMs, particularly Node.js 20 packages. One highlighted vulnerability (CVE-2025-59464) involves a memory leak in Node.js's OpenSSL integration when converting X.509 certificate fields to UTF-8, causing memory to be allocated without being freed. This can be exploited remotely via repeated TLS connections to cause resource exhaustion and denial of service. The advisory lists multiple CVEs and CWE categories related to resource allocation, authentication, and information exposure. The update includes new RPM versions for nodejs20 and related components. However, the vendor advisory does not explicitly state that a fix for CVE-2025-59464 or other CVEs is currently available or deployed, and mitigation options for this specific memory leak are noted as unavailable or insufficient per Red Hat criteria.
Potential Impact
The primary impact is denial of service through resource exhaustion caused by a memory leak in Node.js's OpenSSL integration. Remote attackers can trigger steady memory growth by repeatedly establishing TLS connections, potentially leading to application or system instability. Other listed CVEs and CWEs suggest additional security concerns related to authentication bypass, information exposure, and resource management, but detailed impact descriptions are limited. No known exploits in the wild have been reported.
Mitigation Recommendations
The vendor advisory indicates that mitigation for the Node.js memory leak (CVE-2025-59464) is either not available or does not meet Red Hat's criteria for deployment. No explicit patch availability is confirmed in the advisory text. Users should monitor Red Hat's official errata and update channels for forthcoming fixes. Until a fix is released, consider limiting exposure of affected services to untrusted networks or applying any vendor-recommended workarounds if provided in future advisories.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2781
- Cve Count
- 6
- Additional Cves
- ["CVE-2025-55131","CVE-2025-55132","CVE-2025-59465","CVE-2025-59466","CVE-2026-21637"]
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6a27e99f8dd33fbd8516d255
Added to database: 06/09/2026, 10:23:27 UTC
Last enriched: 08/16/2026, 18:06:12 UTC
Last updated: 09/13/2026, 22:01:30 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.